Loki Intelligence — Security Briefs · Published

Daily Security Brief: WordPress Exploitation, Chrome Zero-Day, ICS Risks

Today’s brief highlights active exploitation against widely used WordPress plugins and a Chrome V8 zero-day requiring rapid patching. CISA also published multiple industrial advisories affecting automation, VPN, discovery, and control systems.

Signal 01 · The Hacker News

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Wordfence reports large-scale exploitation attempts against critical flaws in Super Forms and Elementor Pro WordPress plugins. The activity shows attackers quickly targeting internet-facing CMS components after disclosure.

Why it matters: Inventory exposed WordPress sites, prioritize plugin updates, review web application logs, and consider temporary hardening or disabling affected components where patching is delayed.

Source: The Hacker News

Signal 02 · CISA

Rockwell Automation 1756-ENBT Module

CISA warns that a vulnerability in Rockwell Automation 1756-ENBT modules could cause affected devices to crash and require a restart. The issue affects all listed versions of the module.

Why it matters: Engineering teams should assess operational exposure, apply vendor mitigations, restrict network access to control components, and plan maintenance windows for remediation.

Source: CISA

Signal 03 · CISA

Inductive Automation Ignition

CISA disclosed an Inductive Automation Ignition issue where authenticated users may gain the ability to create projects improperly. Affected deployments include Ignition versions up to 8.1.53.

Why it matters: Review user roles and project permissions, upgrade affected systems, and monitor for unexpected project creation or configuration changes in OT environments.

Source: CISA

Signal 04 · CISA

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

CISA reported a vulnerability in OPC Foundation OPC UA LocalDiscoveryServer installers that could expose a high-privilege terminal during installation. The issue affects installer versions before 1.04.420.

Why it matters: Use updated installers, validate software sources, limit administrative installation sessions, and treat deployment workstations as sensitive assets.

Source: CISA

Signal 05 · CISA

IXON VPN Client

CISA published an advisory for IXON VPN Client versions before 1.4.7 involving elevated remote code execution risk on systems running the client. The product is commonly tied to remote industrial access workflows.

Why it matters: Update VPN clients promptly, reduce unnecessary remote access, enforce endpoint controls, and monitor privileged systems that bridge IT and OT networks.

Source: CISA

Signal 06 · The Hacker News

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google released Chrome updates fixing 12 vulnerabilities, including an actively exploited high-severity V8 type confusion flaw. The zero-day increases urgency for browser patch deployment across managed fleets.

Why it matters: Push Chrome updates quickly, verify browser version compliance, restart stale sessions, and prioritize users with elevated privileges or high-risk browsing exposure.

Source: The Hacker News

Signal 07 · The Hacker News

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI announced GPT-6 Astra and said it has reached a critical cybersecurity capability threshold while blocking proof-of-concept exploit requests. The release reflects growing pressure to balance AI security utility with misuse controls.

Why it matters: Security leaders should update AI governance, define approved defensive use cases, monitor sensitive prompts, and ensure teams do not rely on public models for unvetted exploit research.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.