Loki Intelligence — Security Briefs · Published
Daily Security Brief: Exploited Apps, AI Abuse, and Cloud Disruption
Today’s brief highlights active exploitation of enterprise software flaws, ransomware-linked AI tool use, and growing risk around exposed AI credentials. Teams should prioritize KEV-driven patching, API key governance, resilient identity operations, and monitoring for attacker adaptation around AI-assisted workflows.
Signal 01 · CISA
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild.
Why it matters: Treat KEV additions as urgent remediation signals: inventory PaperCut exposure, apply vendor fixes, restrict administrative access, and review logs for suspicious activity.
Source: CISA
Signal 02 · The Hacker News
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Researchers report active exploitation of critical Langflow and Ruby on Rails flaws tied to credential probing and command-and-control activity.
Why it matters: Internet-facing developer and application frameworks need fast patch cycles, secrets monitoring, and network controls that limit outbound abuse after compromise.
Source: The Hacker News
Signal 03 · The Hacker News
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Aurora ransomware-linked operators were observed using the Cursor AI coding assistant during intrusions against multiple targets, according to security researchers.
Why it matters: Organizations should govern AI developer tools like any other privileged software: define approved use, log access, monitor abnormal automation, and protect workspace tokens.
Source: The Hacker News
Signal 04 · The Hacker News
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR disclosed incidents in which attackers obtained an API key and consumed roughly $600,000 in AI service credits.
Why it matters: AI API keys can create major financial and operational exposure; enforce key rotation, scoped permissions, spend limits, anomaly alerts, and rapid revocation procedures.
Source: The Hacker News
Signal 05 · The Hacker News
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Researchers described a UAC-0099 malware tactic intended to interfere with AI-assisted analysis by embedding misleading prompt content.
Why it matters: Security teams using AI for malware triage should treat model output as untrusted, preserve human review, and harden analysis pipelines against prompt-manipulation attempts.
Source: The Hacker News
Signal 06 · BleepingComputer
Cronos blockchain restarts after $74 million Tectonic exploit
Cronos resumed activity after a price-manipulation incident affecting the Tectonic lending platform enabled about $74 million in unauthorized borrowing.
Why it matters: DeFi teams should strengthen oracle risk controls, circuit breakers, liquidity monitoring, and incident communication plans for market-manipulation scenarios.
Source: BleepingComputer
Signal 07 · BleepingComputer
Massive Microsoft 365 outage causes auth issues, service failures
Microsoft investigated a broad Microsoft 365 service issue affecting authentication, Exchange Online mail flow, and related cloud services.
Why it matters: Cloud outages can resemble security events; maintain alternate communication paths, status-page runbooks, dependency maps, and identity contingency procedures.
Source: BleepingComputer
Brief sources
Related briefs
- Cloud Pentest Checklist for SaaS Teams
- Automated Vulnerability Assessment vs Manual Pentest
- What Is AI Agent Security Testing?
Relevant Loki service: SKYEN web & API pentesting.