Loki Intelligence — Security Briefs · Published

Daily Security Brief: KEV Update, WordPress RCE Risk, PLC Threats

Today’s brief highlights active exploitation risks, exposed enterprise platforms, and continued abuse of weak authentication controls. Teams should prioritize KEV-driven patching, MFA coverage reviews, third-party incident monitoring, and stronger validation of recovery or response providers.

Signal 01 · CISA

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-64849, an MLflow server-side request forgery issue, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

Why it matters: Organizations using MLflow should treat this as an urgent remediation item, verify exposure, and align patch timelines with KEV-driven risk management.

Source: CISA

Signal 02 · The Hacker News

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Researchers reported a critical Elementor Pro WordPress plugin vulnerability that could allow unauthenticated file upload leading to code execution on affected sites.

Why it matters: Product and web teams should inventory WordPress plugins, update Elementor Pro quickly, and monitor for suspicious file changes or unexpected admin activity.

Source: The Hacker News

Signal 03 · BleepingComputer

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

U.S. agencies warned that attackers are using AI-generated scripts in activity targeting Siemens S7 Series PLCs used in critical infrastructure environments.

Why it matters: OT teams should review PLC exposure, enforce segmentation, restrict engineering access, and improve monitoring for unauthorized logic or configuration changes.

Source: BleepingComputer

Signal 04 · BleepingComputer

Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress reported a sharp rise in password spraying, including a large campaign that abused legacy authentication paths and inconsistent MFA enforcement.

Why it matters: Security teams should disable legacy authentication, enforce MFA across all login flows, tune detection for distributed failed logins, and review conditional access gaps.

Source: BleepingComputer

Signal 05 · BleepingComputer

Rogue ransomware affiliate poses as recovery firm to steal payments

A suspected ransomware affiliate is reportedly posing as a recovery company, approaching victims before incidents become public and offering paid decryption or data deletion claims.

Why it matters: Incident response teams should verify recovery vendors, control victim communications, and warn executives that unsolicited recovery offers may be part of the extortion operation.

Source: BleepingComputer

Signal 06 · BleepingComputer

Sakura Internet hack exposes data of up to 1.36 million accounts

Sakura Internet disclosed unauthorized access to a sales management system containing customer contract and membership data for up to 1.36 million accounts.

Why it matters: Customers should watch for targeted phishing and account abuse, while vendors should reassess access controls, logging, and segmentation around customer management systems.

Source: BleepingComputer

Signal 07 · The Hacker News

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

OpenAI paused reinforcement learning training for newer models while expanding safeguards and monitoring intended to reduce unsafe model behavior.

Why it matters: AI product teams should track frontier model safety practices and ensure their own deployment processes include monitoring, rollback plans, and risk reviews before release.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.