Loki Intelligence — Security Briefs · Published

Daily Security Brief: Exploited Apps, AI Abuse, and Cloud Disruption

Today’s brief highlights active exploitation of enterprise software flaws, ransomware-linked AI tool use, and growing risk around exposed AI credentials. Teams should prioritize KEV-driven patching, API key governance, resilient identity operations, and monitoring for attacker adaptation around AI-assisted workflows.

Signal 01 · CISA

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild.

Why it matters: Treat KEV additions as urgent remediation signals: inventory PaperCut exposure, apply vendor fixes, restrict administrative access, and review logs for suspicious activity.

Source: CISA

Signal 02 · The Hacker News

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Researchers report active exploitation of critical Langflow and Ruby on Rails flaws tied to credential probing and command-and-control activity.

Why it matters: Internet-facing developer and application frameworks need fast patch cycles, secrets monitoring, and network controls that limit outbound abuse after compromise.

Source: The Hacker News

Signal 03 · The Hacker News

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Aurora ransomware-linked operators were observed using the Cursor AI coding assistant during intrusions against multiple targets, according to security researchers.

Why it matters: Organizations should govern AI developer tools like any other privileged software: define approved use, log access, monitor abnormal automation, and protect workspace tokens.

Source: The Hacker News

Signal 04 · The Hacker News

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

METR disclosed incidents in which attackers obtained an API key and consumed roughly $600,000 in AI service credits.

Why it matters: AI API keys can create major financial and operational exposure; enforce key rotation, scoped permissions, spend limits, anomaly alerts, and rapid revocation procedures.

Source: The Hacker News

Signal 05 · The Hacker News

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Researchers described a UAC-0099 malware tactic intended to interfere with AI-assisted analysis by embedding misleading prompt content.

Why it matters: Security teams using AI for malware triage should treat model output as untrusted, preserve human review, and harden analysis pipelines against prompt-manipulation attempts.

Source: The Hacker News

Signal 06 · BleepingComputer

Cronos blockchain restarts after $74 million Tectonic exploit

Cronos resumed activity after a price-manipulation incident affecting the Tectonic lending platform enabled about $74 million in unauthorized borrowing.

Why it matters: DeFi teams should strengthen oracle risk controls, circuit breakers, liquidity monitoring, and incident communication plans for market-manipulation scenarios.

Source: BleepingComputer

Signal 07 · BleepingComputer

Massive Microsoft 365 outage causes auth issues, service failures

Microsoft investigated a broad Microsoft 365 service issue affecting authentication, Exchange Online mail flow, and related cloud services.

Why it matters: Cloud outages can resemble security events; maintain alternate communication paths, status-page runbooks, dependency maps, and identity contingency procedures.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki service: SKYEN web & API pentesting.