Loki Intelligence — Security Briefs · Published
Daily Security Brief: AI Tooling, Ransomware, and Endpoint Trust Risks
Ransomware and data-extortion activity remain prominent, while attackers continue to blend into trusted workflows through AI tools, signed software, and user-approved exclusions. Security teams should tighten identity controls, monitor developer and endpoint activity, and reduce accumulated access risk across legacy infrastructure.
Signal 01 · The Hacker News
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Researchers report that Aurora ransomware operators used the Cursor AI coding assistant during intrusions against multiple targets. The activity shows how legitimate AI developer tools can become part of attacker workflows once access is obtained.
Why it matters: Treat AI coding tools as privileged software: log usage, govern access, monitor unusual automation, and ensure developer endpoints are covered by EDR and identity controls.
Source: The Hacker News
Signal 02 · The Hacker News
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
This weekly roundup highlights several recurring risk themes, including exposed router functionality, proxy infrastructure tied to espionage, AI agents behaving unexpectedly, and older vulnerabilities being reused in new chains.
Why it matters: Prioritize fundamentals: patch known flaws, audit internet-facing devices, review AI-agent permissions, and watch for logging gaps that could hide post-compromise activity.
Source: The Hacker News
Signal 03 · BleepingComputer
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin’s city administration confirmed data theft after the Rhysida ransomware group claimed responsibility and attempted extortion through its leak site. The incident reinforces the public-sector exposure to data-theft-driven ransomware campaigns.
Why it matters: Organizations should validate backup recovery, segment sensitive systems, prepare leak-response playbooks, and monitor for stolen data that could enable follow-on fraud or phishing.
Source: BleepingComputer
Signal 04 · BleepingComputer
File servers are here to stay. Here’s how to manage them securely
File servers remain central to many environments, but long-lived shares often accumulate excessive permissions and unclear ownership. The guidance emphasizes practical administration practices that support least privilege.
Why it matters: Regularly review permissions, assign data owners, remove stale access, and use automation where possible to reduce exposure from misconfigured shared storage.
Source: BleepingComputer
Signal 05 · The Hacker News
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Silver Fox has been observed distributing ValleyRAT through signed adware that can appear trustworthy to users and security tools. The campaign benefits when users place unwanted software into antivirus exclusions.
Why it matters: Do not rely on code signing alone as a trust signal; restrict user-managed exclusions, monitor trusted-process abuse, and flag adware installations on corporate endpoints.
Source: The Hacker News
Signal 06 · The Hacker News
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Anthropic’s Compliance API for Claude Code gives security teams more visibility into how the coding agent interacts with files, commands, tools, and local credentials. The broader issue is that developer AI agents can act with the same authority as the user running them.
Why it matters: Apply identity governance to AI coding agents, collect audit logs, limit local credential exposure, and define policies for approved tool use in engineering environments.
Source: The Hacker News
Signal 07 · BleepingComputer
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft confirmed that the Windows 11 KB5120998 preview update may reset mouse settings on affected systems. While not a security flaw, it may create helpdesk noise and user friction after deployment.
Why it matters: Test preview updates before broad rollout, communicate known issues to support teams, and track configuration drift that could affect accessibility or productivity.
Source: BleepingComputer
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.