Loki Intelligence — Security Briefs · Published

Daily Brief: Active Exploitation Hits AI, DevOps, VoIP, and Exchange

Today’s risk is concentrated around internet-facing systems where critical flaws are already being exploited soon after disclosure. Teams should prioritize emergency patching, exposure review, credential rotation, and detection for abnormal admin, token, and mailbox access.

Signal 01 · The Hacker News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

JFrog Artifactory deployments are being targeted through a critical authentication bypass that can allow attackers to create administrative tokens. Exploitation was reported only days after the issue became public.

Why it matters: Artifactory often holds build artifacts, secrets, and software supply chain access; patch quickly, audit token creation, and rotate suspicious or unused admin credentials.

Source: The Hacker News

Signal 02 · The Hacker News

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Researchers demonstrated that an AI assistant could help adapt an existing PLC exploit across related industrial controller models. The work highlights how automation may reduce the effort needed to repurpose known OT attack techniques.

Why it matters: Asset owners should not assume model variation provides protection; segment PLC networks, apply vendor fixes, and monitor engineering workstation activity.

Source: The Hacker News

Signal 03 · The Hacker News

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Sangoma Switchvox systems are under active attack through a critical unauthenticated vulnerability affecting enterprise VoIP environments. Reports indicate attackers are using the flaw to gain remote command capability.

Why it matters: VoIP platforms are often internet reachable and trusted internally; patch immediately, restrict management access, and review call server logs for unusual process or network activity.

Source: The Hacker News

Signal 04 · BleepingComputer

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Attackers are exploiting a critical Langflow vulnerability to access sensitive credentials used by AI application workflows. Reported theft includes cloud keys, API tokens, and other secrets.

Why it matters: AI builder tools can become high-value secret stores; update Langflow, remove public exposure where possible, and rotate OpenAI, AWS, and application keys.

Source: BleepingComputer

Signal 05 · CISA

Rockwell Automation FactoryTalk Activation Manager

CISA published an advisory for Rockwell Automation FactoryTalk Activation Manager affecting supported industrial environments. The issue involves weak controls around repeated authentication attempts.

Why it matters: Industrial licensing and management components can provide operational footholds; apply vendor mitigations, limit access to trusted hosts, and watch for repeated login failures.

Source: CISA

Signal 06 · BleepingComputer

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Thousands of internet-exposed Microsoft Exchange servers remain vulnerable to a high-severity authentication bypass. The exposure could enable attackers to take control of user mailboxes.

Why it matters: Mailbox compromise supports fraud, data theft, and lateral movement; patch Exchange, reduce external exposure, and review mailbox delegation and access anomalies.

Source: BleepingComputer

Signal 07 · The Hacker News

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

New reporting links exploitation of Langflow and Ruby on Rails flaws to credential probing and command-and-control activity. The activity shows attackers chaining web application exposure with follow-on access attempts.

Why it matters: Treat public app flaws as credential compromise events; patch affected services, rotate secrets, and inspect outbound traffic for unusual destinations.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.