Loki Intelligence — Security Briefs · Published

Daily Brief: Active Exploitation, Cloud IAM Risk, and Supply Chain Malware

Today’s brief is dominated by fast-moving exploitation of enterprise software and identity infrastructure, with Zimbra, GitLab, and Microsoft Entra ID drawing urgent attention. Supply chain and collaboration-platform abuse remain active themes, underscoring the need for patch discipline, package governance, and stronger phishing controls.

Signal 01 · CISA

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added a Zimbra Collaboration Suite command injection flaw, CVE-2026-73570, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

Why it matters: Teams running Zimbra should treat KEV inclusion as a high-priority remediation signal, validate exposure, and accelerate patch or mitigation timelines.

Source: CISA

Signal 02 · The Hacker News

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478, a high-severity code injection issue, is reportedly being exploited shortly after disclosure, highlighting a narrow patch window for internet-facing developer platforms.

Why it matters: Engineering and security teams should quickly inventory GitLab instances, apply vendor fixes, and review access logs for suspicious activity around disclosure dates.

Source: The Hacker News

Signal 03 · The Hacker News

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researchers found 14 malicious npm packages posing as utility libraries while delivering a Linux backdoor known as RedC2 4.0 with AI-assisted command-and-control features.

Why it matters: Product and platform teams should tighten dependency review, monitor newly introduced packages, and enforce software composition analysis in CI/CD pipelines.

Source: The Hacker News

Signal 04 · The Hacker News

Wazuh and AI For Enhanced SOC Workflows

The article discusses how AI can support SOC workflows by helping analysts process alerts, identify patterns, and improve operational decision-making when paired with security monitoring platforms.

Why it matters: Security leaders adopting AI in detection workflows should focus on analyst augmentation, validation, auditability, and controls that reduce alert fatigue without creating blind trust.

Source: The Hacker News

Signal 05 · BleepingComputer

Microsoft patches max severity code execution, privilege escalation flaws

Microsoft released fixes for a maximum-severity Entra ID issue affecting identity and access management, along with other serious code execution and privilege escalation flaws.

Why it matters: Identity systems are high-impact targets, so organizations should prioritize cloud IAM patch verification, review privileged access, and monitor for unusual authentication or admin activity.

Source: BleepingComputer

Signal 06 · The Hacker News

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

The Hacker News reported on a CVSS 10.0 Entra ID remote code execution flaw and noted that Microsoft later corrected its advisory to say the issue had not been exploited.

Why it matters: Even without confirmed exploitation, maximum-severity identity vulnerabilities warrant rapid remediation, change tracking, and clear internal communications to avoid confusion from advisory updates.

Source: The Hacker News

Signal 07 · BleepingComputer

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A new malware family called SynkLoader is being distributed through Microsoft Teams phishing lures and uses a fake lock screen to steal credentials.

Why it matters: Organizations should harden Teams external communication settings, train users on collaboration-app phishing, and monitor for credential theft indicators following suspicious chats or file shares.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki service: SKYEN web & API pentesting.