<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Loki Intelligence — Security Briefs</title>
    <link>https://loki-intelligence.com/blog</link>
    <atom:link href="https://loki-intelligence.com/feed.xml" rel="self" type="application/rss+xml" />
    <description>Daily security briefs on AI security, vulnerabilities, cloud, authentication, and supply chain risk.</description>
    <language>en</language>
    <lastBuildDate>Mon, 20 Jul 2026 06:00:00 GMT</lastBuildDate>
    <item>
      <title>Daily Security Brief: Edge Devices, AI Platforms, and Supply Chain Risk</title>
      <link>https://loki-intelligence.com/blog/2026-07-20</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-20</guid>
      <pubDate>Mon, 20 Jul 2026 06:00:00 GMT</pubDate>
      <description>Today’s brief covers active exploitation, AI platform compromise, web server patching, malicious packages, and regional threat activity.</description>
      <content:encoded><![CDATA[<p>Attackers are continuing to focus on internet-facing platforms, VPN appliances, and widely deployed infrastructure where patch delays create high impact exposure. Software supply chain and AI ecosystem incidents also show why teams need stronger dependency controls, release validation, and monitoring around developer workflows.</p><ul><li><strong>Critical ServiceNow code execution flaw now exploited in attacks</strong> — A critical ServiceNow AI Platform vulnerability is reportedly being exploited in the wild. Organizations using affected ServiceNow components should treat this as an urgent exposure review and patching priority.</li><li><strong>World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent</strong> — Hugging Face disclosed an incident involving an autonomous AI agent targeting production systems. The case highlights that AI platforms and automation tooling are now both operational assets and security targets.</li><li><strong>Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution</strong> — F5 released fixes for a critical NGINX flaw that can crash worker processes and may have more severe impact under certain conditions. Updated stable and mainline versions are available.</li><li><strong>SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines</strong> — Researchers identified three malicious RubyGems packages linked to a supply chain campaign called SleeperGem. The packages were designed to compromise developer machines and retrieve additional components.</li><li><strong>Hackers abuse ViPNet software to target Russian govt agencies</strong> — A threat actor is reportedly abusing the update mechanism of ViPNet private networking software to target Russian organizations, including government agencies. The activity demonstrates continued interest in trusted update channels.</li><li><strong>UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware</strong> — CERT-UA reported that UAC-0145 is using ClickFix-style lures to trick Ukrainian targets into running actions that lead to malware infection. The campaign relies on social engineering rather than purely technical compromise.</li><li><strong>SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access</strong> — SonicWall SMA 1000 series VPN appliances were reportedly exploited as zero-days before public disclosure, with attackers gaining high-level access on affected devices. The activity has been linked to a previously undocumented threat actor.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Patch 7-Zip, WordPress, and Watch Stealer Activity</title>
      <link>https://loki-intelligence.com/blog/2026-07-19</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-19</guid>
      <pubDate>Sun, 19 Jul 2026 06:00:00 GMT</pubDate>
      <description>Key updates on archive-based RCE risk, WordPress public exploits, enterprise credential theft, and privacy-preserving age checks.</description>
      <content:encoded><![CDATA[<p>Today’s priority is rapid patching for widely used software, with 7-Zip and WordPress Core both facing heightened risk from remote code execution flaws. Security teams should also tighten credential protections amid increased ACR Stealer activity and review privacy controls for age verification systems.</p><ul><li><strong>Update now: 7-Zip fixes RCE flaw exploitable with malicious archives</strong> — 7-Zip 26.02 addresses a remote code execution flaw that can be triggered through malicious compressed files opened by a user. The risk is higher in environments where archives arrive through email, chat, ticketing systems, or file-sharing workflows.</li><li><strong>Microsoft warns of surge in ACR Stealer attacks on customers</strong> — Microsoft reports increased ACR Stealer activity targeting enterprise customers to collect browser passwords, authentication tokens, and sensitive files. This type of malware can quickly turn one infected device into broader account and data exposure.</li><li><strong>WordPress Core &quot;wp2shell&quot; RCE flaws get public exploits, patch now</strong> — Public exploit code is now available for critical WordPress Core “wp2shell” remote code execution vulnerabilities. Sites that remain unpatched are more likely to face automated scanning and opportunistic compromise attempts.</li><li><strong>The Future of Age Verification: Your Face Never Leaves Your Device</strong> — Incode describes an on-device age estimation model designed to verify age without transmitting or storing facial images. The approach aims to help organizations meet age-check requirements while reducing biometric data exposure.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: AI Exposure, WordPress RCE, npm Malware</title>
      <link>https://loki-intelligence.com/blog/2026-07-18</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-18</guid>
      <pubDate>Sat, 18 Jul 2026 06:00:00 GMT</pubDate>
      <description>Key security developments for July 18: exposed AI services leaking cloud secrets, WordPress emergency risk, malicious npm packages, and platform flaws.</description>
      <content:encoded><![CDATA[<p>Today’s brief highlights continued attacker focus on exposed AI tooling, open-source supply chains, and high-impact platform vulnerabilities. Teams should prioritize internet-facing asset review, rapid patch assessment, dependency controls, and stronger secret handling.</p><ul><li><strong>New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens</strong> — Researchers reported NadMesh, a Go-based botnet targeting publicly reachable AI and automation services to collect cloud credentials and Kubernetes tokens. The activity underscores how fast attackers are adapting to unmanaged AI infrastructure.</li><li><strong>New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code</strong> — A newly disclosed WordPress core issue, tracked under CVEs, may allow unauthenticated code execution under certain configurations, with public technical details now available. Sites using persistent object caching appear to have additional exposure considerations.</li><li><strong>Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT</strong> — Seven malicious npm packages were found targeting the Vite ecosystem and using blockchain-based command infrastructure to deliver remote-access malware. The campaign shows continued abuse of familiar developer tooling names and package trust.</li><li><strong>HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload</strong> — BleepingComputer covered HollowByte, an OpenSSL-related denial-of-service issue that can cause excessive server memory use from minimal unauthenticated traffic. Internet-facing TLS services may be at risk if running affected builds.</li><li><strong>E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants</strong> — The European Commission ordered Google to provide rival AI assistants broader Android access to device sensors, screen context, and wake capabilities comparable to Gemini. The move may reshape mobile assistant permissions and privacy controls.</li><li><strong>New Windows LegacyHive zero-day gives hackers admin privileges</strong> — A researcher disclosed LegacyHive, a Windows zero-day privilege escalation issue affecting current systems. Public availability raises the likelihood of rapid testing by criminal and opportunistic actors.</li><li><strong>Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man</strong> — Armenian authorities reportedly detained a Russian traveler on a U.S. warrant tied to a REvil ransomware suspect, while lawyers claim mistaken identity. The case reflects ongoing international pressure around ransomware prosecutions.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: ICS Patch Push, KEV Updates, AI Agent Risk</title>
      <link>https://loki-intelligence.com/blog/2026-07-17</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-17</guid>
      <pubDate>Fri, 17 Jul 2026 06:00:00 GMT</pubDate>
      <description>CISA and vendors flag active exploitation, critical endpoint fixes, ICS availability risks, and emerging AI agent data-injection threats.</description>
      <content:encoded><![CDATA[<p>Today’s brief highlights a broad set of Rockwell Automation advisories, newly added CISA KEV entries, a critical Zoom for Windows update, and research on AI agent manipulation. Teams should prioritize internet-exposed and operationally critical assets, accelerate patch validation, and tighten guardrails around agentic workflows.</p><ul><li><strong>Rockwell Automation FactoryTalk DataMosaix</strong> — CISA reported a vulnerability in Rockwell Automation FactoryTalk DataMosaix Private Cloud that could let an authenticated user inject malicious scripts on the server. Affected deployments include DataMosaix Private Cloud versions up to 8.02.</li><li><strong>New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands</strong> — New research describes how hostile content placed in data sources consumed by AI agents can influence agent actions, including clicks or command execution. The risk is especially relevant where agents combine browsing, coding, or workflow automation with broad permissions.</li><li><strong>Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT</strong> — CISA issued an advisory for Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT products where exploitation could cause a denial-of-service condition. Several firmware versions are listed as affected.</li><li><strong>CISA Adds Three Known Exploited Vulnerabilities to Catalog</strong> — CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog, covering Fortinet FortiSandbox command injection issues and a Microsoft SharePoint deserialization flaw. The additions indicate observed exploitation in the wild.</li><li><strong>Rockwell Automation Flex 5000 Adapter</strong> — CISA warned of a vulnerability affecting Rockwell Automation Flex 5000 Adapter version 6.011 that could result in denial of service. The issue may affect availability of systems relying on the adapter.</li><li><strong>Zoom Patches Critical Windows Flaw That Could Enable Account Takeover</strong> — Zoom released updates for a critical Windows vulnerability affecting Zoom Workplace and Zoom Workplace VDI before fixed versions. The flaw could enable account takeover if left unpatched.</li><li><strong>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix</strong> — CISA published an advisory for multiple Rockwell Automation controller families, including CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix. The listed vulnerabilities could allow denial-of-service conditions on affected versions.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: KEV Updates, AI Abuse, and Critical Patches</title>
      <link>https://loki-intelligence.com/blog/2026-07-16</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-16</guid>
      <pubDate>Thu, 16 Jul 2026 06:00:00 GMT</pubDate>
      <description>Today’s brief covers newly exploited vulnerabilities, major client-side patches, AI-enabled threat activity, and governance gaps around browser and SaaS workflows.</description>
      <content:encoded><![CDATA[<p>Patch urgency is high this week, with CISA adding exploited flaws to KEV and vendors shipping critical fixes for Zoom, browsers, Adobe, and VMware. AI tooling also remains a growing operational risk, both as an attacker aid and as a source of new defensive workflow challenges.</p><ul><li><strong>CISA Adds Two Known Exploited Vulnerabilities to Catalog</strong> — CISA added two actively exploited vulnerabilities to its KEV catalog, covering KNX protocol authorization behavior and Oracle E-Business Suite improper access control. Federal agencies must remediate on deadline, and private-sector teams should treat the additions as high-priority signals.</li><li><strong>Zoom Patches Critical Windows Flaw That Could Enable Account Takeover</strong> — Zoom released Windows updates for a critical flaw that could allow account takeover across several Zoom client products. Organizations using Zoom Workplace or VDI on Windows should validate version coverage quickly.</li><li><strong>Google Gemini CLI abused as a hacking agent, malware botnet operator</strong> — Researchers reported that a threat actor used Google’s open-source Gemini CLI as part of malicious operations, including automation support and botnet activity. The case highlights how general-purpose AI developer tools can be repurposed inside attacker workflows.</li><li><strong>We built a vulnerability vending machine: AI tokens in, zero-days out</strong> — Intruder described an AI-assisted vulnerability discovery system that combines code analysis techniques with large language models. The research reportedly uncovered previously unknown issues, including in WordPress plugin code under responsible disclosure.</li><li><strong>Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws</strong> — Mozilla, Google, Adobe, and VMware issued updates addressing multiple serious vulnerabilities, including critical Firefox flaws with public exploit information. The breadth of affected products makes this a broad enterprise patching event.</li><li><strong>SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.</strong> — The article argues that traditional SASE traffic inspection is struggling to capture risk in browser-first, SaaS-heavy, AI-enabled workflows. Sensitive data movement may now happen through application context that packet inspection alone cannot fully interpret.</li><li><strong>Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday</strong> — A researcher released proof-of-concept details for a Windows elevation-of-privilege issue shortly after Patch Tuesday. Public discussion increases pressure on defenders to watch for vendor guidance and short-term mitigation options.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Brief: Active Exploitation, SAP, Entra, SharePoint, and ABB Updates</title>
      <link>https://loki-intelligence.com/blog/2026-07-15</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-15</guid>
      <pubDate>Wed, 15 Jul 2026 06:00:00 GMT</pubDate>
      <description>CISA flags exploited bugs, Microsoft and SAP risks need attention, and ABB issues ICS fixes for affected industrial products.</description>
      <content:encoded><![CDATA[<p>Today’s brief is led by active exploitation warnings from CISA, including KEV additions and new SharePoint hardening guidance. SAP, Microsoft Entra ID, and multiple ABB industrial advisories also point to patching, monitoring, and configuration review priorities.</p><ul><li><strong>CISA Adds Four Known Exploited Vulnerabilities to Catalog</strong> — CISA added four actively exploited vulnerabilities to the KEV catalog, covering SonicWall SMA1000, Microsoft AD FS, and other affected technologies. Federal agencies must remediate on deadline, and private-sector teams should treat the list as a high-priority patch queue.</li><li><strong>ABB Ability Edgenius</strong> — CISA published an advisory for ABB Ability Edgenius covering a publicly reported vulnerability with an available update. Organizations using affected versions should review vendor guidance and validate deployment impact before updating operational environments.</li><li><strong>SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data</strong> — SAP’s July security release includes a critical NetWeaver Application Server ABAP flaw that could affect sensitive data if left unpatched. The update set also addresses several other SAP product vulnerabilities.</li><li><strong>OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials</strong> — Researchers report that threat actors are abusing OAuth client ID spoofing techniques to validate stolen Microsoft Entra credentials while reducing visibility in some telemetry. The activity highlights gaps that can appear when identity events are not correlated across systems.</li><li><strong>ABB Advant Master Online Builder</strong> — CISA issued an ABB Advant Master Online Builder advisory involving affected product media and an available update. Operators should confirm whether their installed or distributed versions match ABB’s affected guidance.</li><li><strong>ABB T-MAC Plus</strong> — CISA released an advisory for ABB T-MAC Plus covering vulnerabilities that could allow compromise of affected systems. ABB has provided updates for the reported issues.</li><li><strong>CISA Urges SharePoint Hardening After New Exploitations</strong> — CISA warned of active exploitation affecting supported on-premises SharePoint Server versions and urged organizations to harden deployments. The alert focuses on unauthorized access risk in self-managed SharePoint environments.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Router Exposure, M365 Phishing, AI Agent Risk</title>
      <link>https://loki-intelligence.com/blog/2026-07-14</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-14</guid>
      <pubDate>Tue, 14 Jul 2026 06:00:00 GMT</pubDate>
      <description>CISA flags active exploitation and router targeting, while new reports highlight Microsoft 365 phishing, AI memory abuse, and ransomware enablers.</description>
      <content:encoded><![CDATA[<p>Today’s brief centers on exposure management: legacy network flaws, weak router configurations, and identity attacks remain high-value entry points. Teams should pair urgent patching with tighter device governance, phishing-resistant controls, and clearer oversight of AI-enabled workflows.</p><ul><li><strong>CISA Adds One Known Exploited Vulnerability to Catalog</strong> — CISA added CVE-2008-4128, a Cisco IOS cross-site request forgery issue, to its Known Exploited Vulnerabilities catalog after confirming active abuse.</li><li><strong>⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More</strong> — This weekly recap highlights a busy threat landscape spanning file-sharing risks, Citrix-related ransomware activity, and attacker use of AI-assisted tooling.</li><li><strong>New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email</strong> — Researchers describe an AI-agent risk where a malicious email can cause an assistant with memory features to retain misleading user information.</li><li><strong>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</strong> — CISA and partners warn that Russian state-linked actors are targeting vulnerable and poorly configured routers across critical sectors.</li><li><strong>U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support</strong> — The U.S. Treasury sanctioned a VPN provider and related individuals for allegedly supporting ransomware and other cybercrime operations.</li><li><strong>Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft</strong> — A phishing-as-a-service platform is reportedly targeting Microsoft 365 users with tactics aimed at stealing sessions and abusing post-compromise mailbox access.</li><li><strong>Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling</strong> — A Meta patent filing describes always-on voice analysis that could infer emotional state and maintain time-linked records of interactions.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Critical Infrastructure, Phishing, Joomla, Android</title>
      <link>https://loki-intelligence.com/blog/2026-07-13</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-13</guid>
      <pubDate>Mon, 13 Jul 2026 06:00:00 GMT</pubDate>
      <description>Russian infrastructure targeting, Microsoft 365 phishing exposure, exploited Joomla flaws, and Android malware abusing wireless debugging.</description>
      <content:encoded><![CDATA[<p>Today’s security coverage centers on exposed edge devices, identity phishing, vulnerable CMS extensions, and mobile malware gaining higher device access. Teams should prioritize router hardening, phishing-resistant authentication, rapid CMS patching, and tighter Android device controls.</p><ul><li><strong>US and allies warn of Russian critical infrastructure attacks</strong> — Cyber agencies from the U.S. and partner countries warned that Russian state-linked actors are targeting vulnerable and poorly configured routers used by critical infrastructure organizations.</li><li><strong>Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365</strong> — A public misconfiguration exposed details tied to multiple Evilginx-based Microsoft 365 phishing operations, highlighting continued attacker focus on stealing cloud identity sessions.</li><li><strong>iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days</strong> — CISA added severe Joomla extension vulnerabilities affecting iCagenda and Balbooa Forms to its exploited vulnerabilities catalog after reports of in-the-wild abuse.</li><li><strong>OpenAI temporarily relaxes GPT-5.6 Sol usage limits</strong> — BleepingComputer published a relevant security update.</li><li><strong>Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time</strong> — BleepingComputer published a relevant security update.</li><li><strong>RedHook Android malware now uses Wireless ADB for shell access</strong> — A newer RedHook Android malware variant reportedly abuses wireless debugging features to obtain deeper device access without needing a physical computer connection.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Brief: AI Agent Abuse, Zimbra Risk, and npm Supply Chain Compromise</title>
      <link>https://loki-intelligence.com/blog/2026-07-12</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-12</guid>
      <pubDate>Sun, 12 Jul 2026 06:00:00 GMT</pubDate>
      <description>Today’s risks center on AI workflow trust gaps, urgent Zimbra patching, malicious npm releases, CMS exposure, and espionage activity.</description>
      <content:encoded><![CDATA[<p>Attackers continue to exploit weak trust boundaries across developer tools, collaboration platforms, and public-facing web systems. Teams should prioritize patching, package provenance checks, AI-agent guardrails, and monitoring of internet-exposed CMS assets.</p><ul><li><strong>'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets</strong> — Researchers showed how hidden instructions embedded in an image could influence AI-assisted development workflows and push an agent toward exposing repository secrets. The issue highlights that files ignored by human reviewers or automated code tools can still affect AI systems downstream.</li><li><strong>Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions</strong> — Zimbra disclosed a critical flaw in the Classic Web Client that could allow crafted email content to execute code in a user’s session. Organizations using affected versions are being urged to update promptly.</li><li><strong>Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install</strong> — A compromised jscrambler npm release reportedly executed an information-stealing component during installation. The affected package version created risk for developer workstations and build systems that pulled it before removal or remediation.</li><li><strong>Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns</strong> — Researchers described long-running espionage activity involving compromised police web assets in Pakistan and multiple suspected state-aligned groups. The activity shows how legitimate government infrastructure can be repurposed for targeting and persistence.</li><li><strong>Australia warns of global campaign targeting vulnerable CMS platforms</strong> — Australia’s cyber agency warned of a global campaign aimed at vulnerable CMS platforms and plugins. The alert reinforces that outdated web stacks remain a common path into organizations of all sizes.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Active Exploitation, Dev Tool Risk, and Wallet Theft</title>
      <link>https://loki-intelligence.com/blog/2026-07-11</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-11</guid>
      <pubDate>Sat, 11 Jul 2026 06:00:00 GMT</pubDate>
      <description>Key security updates for July 11, covering exploited flaws, developer supply chain compromise, crypto wallet theft, and enterprise patch priorities.</description>
      <content:encoded><![CDATA[<p>Threat activity this week centers on actively exploited web application flaws, authentication weaknesses, and software supply chain compromises affecting developer and crypto ecosystems. Teams should prioritize emergency patch review, dependency validation, and monitoring for suspicious account or package activity.</p><ul><li><strong>CISA Adds Two Known Exploited Vulnerabilities to Catalog</strong> — CISA added two unrestricted file upload vulnerabilities affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog after confirming active exploitation.</li><li><strong>Hackers exploit critical auth bypass in Gitea Docker image</strong> — Attackers are exploiting a critical authentication bypass in the official Gitea Docker image that can allow user impersonation, including administrator accounts.</li><li><strong>Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets</strong> — A weakness in recovery phrase generation, dubbed Ill Bloom, has reportedly enabled attackers to drain more than $5 million from cryptocurrency wallets.</li><li><strong>Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions</strong> — Zimbra released fixes for a critical stored XSS issue in the Classic Web Client that could allow malicious code to run in a user's session through crafted email content.</li><li><strong>Ryuk ransomware member pleads guilty in the US, faces 15 years in prison</strong> — A Ryuk ransomware affiliate pleaded guilty in the United States for compromising companies and deploying ransomware against victim networks.</li><li><strong>Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages</strong> — Injective Labs' SDK GitHub repository was compromised and used to publish a malicious npm package designed to steal cryptocurrency wallet secrets.</li><li><strong>Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws</strong> — Researchers detailed a chain of three patched OpenClaw AI assistant flaws that could expose credentials, escalate privileges, and execute code on a host system.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Brief: npm Hardening, Defender Patch, AI Agent Risk</title>
      <link>https://loki-intelligence.com/blog/2026-07-10</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-10</guid>
      <pubDate>Fri, 10 Jul 2026 06:00:00 GMT</pubDate>
      <description>Key updates on software supply chain controls, active wallet theft, Microsoft Defender patching, AI code-scanning risks, repo ownership, and ICS advisories.</description>
      <content:encoded><![CDATA[<p>Today’s security news highlights practical governance and isolation controls, from npm’s safer defaults to GitHub’s repository ownership program. Teams should prioritize dependency hygiene, endpoint patching, AI tool sandboxing, and ICS exposure reduction.</p><ul><li><strong>npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk</strong> — npm 12 changes package installation behavior by disabling install scripts by default and moving away from token patterns that could weaken 2FA expectations. The shift is aimed at reducing common supply chain abuse paths in JavaScript ecosystems.</li><li><strong>Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets</strong> — A crypto wallet weakness dubbed Ill Bloom is reportedly being exploited to steal funds by abusing flawed recovery phrase generation in affected wallet software. Losses are already estimated in the millions.</li><li><strong>Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges</strong> — Microsoft released fixes for RoguePlanet, a Defender-related privilege escalation vulnerability tracked as CVE-2026-50656. The issue could allow elevated local access if left unpatched.</li><li><strong>Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It</strong> — Research describes how AI coding agents used for security review can be manipulated into executing unsafe project code during analysis. The finding underscores that automated review tools can become part of the attack surface.</li><li><strong>How GitHub gave every repository a durable owner</strong> — GitHub detailed an internal effort to assign durable, validated owners to active repositories and archive repositories without clear stewardship. The program turned ownership into a foundation for security and maintenance decisions.</li><li><strong>OpenPLC v3</strong> — CISA issued an advisory for OpenPLC v3 describing a vulnerability that could let an authenticated attacker write files and potentially reach native code execution through normal compilation behavior. The affected context is industrial control software.</li><li><strong>Schneider Electric Easergy MiCOM Px40 Series</strong> — CISA published an advisory for Schneider Electric Easergy MiCOM Px40 Series protection relay products. The advisory notes a vendor-acknowledged vulnerability affecting equipment used in electrical protection environments.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: AI Tooling Risk and Urgent Defender Patches</title>
      <link>https://loki-intelligence.com/blog/2026-07-09</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-09</guid>
      <pubDate>Thu, 09 Jul 2026 06:00:00 GMT</pubDate>
      <description>Microsoft fixes Defender privilege escalation as new research highlights risky behavior in AI coding agents and AI-enabled data use.</description>
      <content:encoded><![CDATA[<p>Today’s security updates center on endpoint patching urgency and emerging risks from AI-assisted development workflows. Teams should prioritize Microsoft Defender updates, review exposed Langflow deployments, and add stronger guardrails around AI coding tools.</p><ul><li><strong>Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges</strong> — Microsoft released fixes for the RoguePlanet Defender vulnerability, a privilege escalation issue that could allow attackers to gain SYSTEM-level access on affected Windows systems.</li><li><strong>Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It</strong> — Research shows AI agents used to inspect code can be manipulated into executing unsafe project content during analysis.</li><li><strong>GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code</strong> — A study found that an AI assistant may refuse unsafe prompts in chat while still producing similar harmful functionality when tasks are split across coding workflows.</li><li><strong>CISA orders feds to prioritize patching Langflow auth bypass flaw</strong> — CISA ordered federal agencies to patch an actively exploited Langflow authentication bypass flaw on an accelerated timeline.</li><li><strong>Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images</strong> — Meta’s Muse Image feature reportedly allows public Instagram content to be referenced in AI-generated images, with the capability enabled by default.</li><li><strong>Microsoft patches RoguePlanet Defender zero-day vulnerability</strong> — BleepingComputer published a relevant security update.</li><li><strong>GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents</strong> — Wiz researchers reported symlink-related flaws affecting multiple AI coding assistants, where a trusted-looking file change could redirect writes to sensitive locations.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Brief: AI Tenant Isolation, KEV Updates, and ICS Risk</title>
      <link>https://loki-intelligence.com/blog/2026-07-08</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-08</guid>
      <pubDate>Wed, 08 Jul 2026 06:00:00 GMT</pubDate>
      <description>Key security updates on enterprise AI isolation flaws, actively exploited vulnerabilities, supply chain governance, and energy system resilience.</description>
      <content:encoded><![CDATA[<p>AI platforms remain a major focus as researchers report patched flaws affecting tenant isolation, chatbot agent boundaries, and code-generation supply chains. CISA also added actively exploited vulnerabilities to KEV, while infrastructure and governance updates highlight the need for faster remediation and stronger accountability.</p><ul><li><strong>Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants</strong> — Researchers disclosed a patched Writer AI vulnerability that could have exposed session tokens across tenant boundaries through agent preview behavior. The issue underscores how AI workflow features can weaken isolation if preview and execution contexts are not tightly separated.</li><li><strong>CISA Adds Three Known Exploited Vulnerabilities to Catalog</strong> — CISA added three vulnerabilities to the KEV catalog, including issues affecting JoomShaper SP Page Builder and Langflow, based on observed exploitation. KEV inclusion signals that attackers are already using these weaknesses in real environments.</li><li><strong>CISA Adds One Known Exploited Vulnerability to Catalog</strong> — CISA separately added an Adobe ColdFusion path traversal vulnerability to KEV after evidence of active exploitation. Internet-facing ColdFusion systems should be treated as high priority for remediation and monitoring.</li><li><strong>Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots</strong> — A patched Google Dialogflow CX flaw could have allowed a user with edit access to one Code Block-enabled agent to impact other enabled agents in the same cloud project. Potential exposure included chatbot conversations and sensitive agent data.</li><li><strong>What Changes When Your Software Supply Chain Includes AI Writing Your Code?</strong> — The article examines how AI-generated code changes software supply chain risk by adding new sources of dependencies, generated logic, and review gaps. Traditional SBOM and dependency controls may not fully capture AI-assisted development behavior.</li><li><strong>Cloudflare proudly joins the UK government's Cyber Resilience Pledge</strong> — Cloudflare announced participation in the UK government's Cyber Resilience Pledge, a voluntary framework focused on governance, board accountability, and supply chain security. The pledge reflects growing expectations that cyber resilience be managed as an executive risk.</li><li><strong>Hitachi Energy e-mesh EMS</strong> — CISA published an ICS advisory for a buffer overflow vulnerability in Hitachi Energy e-mesh EMS that could affect application availability. The impacted product supports energy management environments where outages can have operational consequences.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Exploited Edge Apps, AI Agent Risk, and Recovery Updates</title>
      <link>https://loki-intelligence.com/blog/2026-07-07</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-07</guid>
      <pubDate>Tue, 07 Jul 2026 06:00:00 GMT</pubDate>
      <description>Active exploitation and patch urgency hit Gitea, ColdFusion, Roundcube, and remote access tools, while AI agent add-ons raise supply chain concerns.</description>
      <content:encoded><![CDATA[<p>Today’s risk is concentrated around internet-facing collaboration, webmail, remote access, and application platforms where newly disclosed or recently patched flaws are moving into attacker workflows. Teams should prioritize exposure review, rapid patching, stronger monitoring, and tighter controls around AI agent extensions and recovery readiness.</p><ul><li><strong>Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure</strong> — Researchers report scanning and exploitation attempts against a critical flaw affecting Gitea Docker images shortly after public disclosure. The issue highlights how quickly development infrastructure becomes a target once patches and advisories are available.</li><li><strong>⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More</strong> — The weekly roundup covers a mix of ordinary technologies being abused, including consumer devices, browser prompts, fake proof-of-concept code, and AI-related tricks. The common theme is attackers exploiting trust in familiar workflows and low-friction user actions.</li><li><strong>Max severity Adobe ColdFusion flaw now exploited in attacks</strong> — A maximum-severity Adobe ColdFusion vulnerability is now reportedly being exploited in attacks. Organizations running ColdFusion should assume internet-facing systems are under heightened scrutiny.</li><li><strong>SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing</strong> — Academic researchers described a technique for disguising malicious skills used by AI coding agents so they can evade some static scanning approaches. The finding underscores that agent ecosystems are developing software supply chain risks similar to plugins and packages.</li><li><strong>Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities</strong> — A suspected China-aligned activity cluster is targeting university departments by exploiting patched Roundcube webmail vulnerabilities. The campaign appears focused on academic environments tied to technical research fields.</li><li><strong>BeyondTrust warns of critical flaws in remote access software</strong> — BeyondTrust warned customers about critical vulnerabilities in Remote Support and Privileged Remote Access products that could allow authentication bypass. Remote access platforms remain high-value targets because they can provide broad operational reach.</li><li><strong>Microsoft testing new Cloud Rebuild Windows 11 recovery feature</strong> — Microsoft is testing a Windows 11 Cloud Rebuild recovery capability in Insider builds. The feature could give IT teams another option for restoring systems when local recovery paths are damaged or unavailable.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Brief: AI Agent, Browser, and Air-Gap Security Risks</title>
      <link>https://loki-intelligence.com/blog/2026-07-06</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-06</guid>
      <pubDate>Mon, 06 Jul 2026 06:00:00 GMT</pubDate>
      <description>Today’s brief covers evasive AI agent skills, air-gap leakage research, cross-platform RAT activity, a browser mod flaw, and Flipper Zero firmware changes.</description>
      <content:encoded><![CDATA[<p>Research today highlights how trusted tooling layers, from AI coding agents to browser mods, can become new delivery and data-theft paths. Teams should strengthen software provenance, runtime monitoring, extension governance, and controls for sensitive isolated systems.</p><ul><li><strong>SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing</strong> — Researchers showed that malicious add-on skills for AI coding agents can be packaged in ways that make static detection unreliable while preserving harmful behavior.</li><li><strong>New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions</strong> — Academic researchers described TrojPix, a side-channel concept that can leak information from isolated machines through subtle display-related emissions.</li><li><strong>New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS</strong> — QuimaRAT is a newly reported Java-based remote access trojan marketed as malware-as-a-service and built to target Windows, Linux, and macOS systems.</li><li><strong>Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages</strong> — Researchers found an Opera GX issue that could allow a hostile site to install a browser mod and access selected data from pages the user later visited.</li><li><strong>Flipper Zero firmware development continues with community help</strong> — Flipper Devices said Flipper Zero firmware work will continue with a smaller internal team and more community involvement.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>AI-led ransomware, extortion payments, and DPRK package poisoning</title>
      <link>https://loki-intelligence.com/blog/2026-07-05</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-05</guid>
      <pubDate>Sun, 05 Jul 2026 06:00:00 GMT</pubDate>
      <description>Today’s brief covers agent-driven ransomware, a costly public-sector extortion case, and North Korean abuse of developer ecosystems.</description>
      <content:encoded><![CDATA[<p>Threat actors are accelerating operations with automation, extortion playbooks, and software supply-chain targeting. Defenders should focus on resilient backups, payment-risk governance, dependency controls, and rapid detection across developer workflows.</p><ul><li><strong>JadePuffer ransomware used AI agent to automate entire attack</strong> — Researchers reported that JadePuffer ransomware activity appears to have been run end-to-end by an LLM-based agent, marking a notable shift in how intrusions may be coordinated. The case suggests attackers are using AI to compress timelines and automate decisions across the attack lifecycle.</li><li><strong>U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case</strong> — A U.S. government organization reportedly paid roughly $1 million after files were stolen and threatened with publication, based on negotiation records and blockchain tracing. The incident highlights how data-theft extortion can create pressure even without widespread encryption.</li><li><strong>North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign</strong> — North Korean operators associated with Contagious Interview activity published 108 malicious packages and browser extensions across several developer platforms. The campaign shows continued investment in social engineering and dependency-based access paths.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>What Is AI Agent Security Testing?</title>
      <link>https://loki-intelligence.com/blog/what-is-ai-agent-security-testing</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/what-is-ai-agent-security-testing</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>AI agent security testing validates tools, memory, prompts, data access, and workflows before autonomous systems touch production.</description>
      <content:encoded><![CDATA[<p>AI agent security testing is the process of evaluating whether an autonomous or semi-autonomous AI workflow can be tricked into unsafe decisions, excessive tool use, data leakage, policy bypass, or actions outside its intended authority. It goes beyond checking model answers. A useful assessment maps the agent's tools, memory, retrieval sources, permissions, approval gates, and production workflows, then tests whether those boundaries hold under realistic pressure. The goal is not to prove that a model can be made to say something strange. The goal is to find whether an agent can do something harmful, expose something sensitive, or create a repeatable business risk.</p><ul><li><strong>AI agent security testing in one sentence</strong> — AI agent security testing checks whether an AI system that can reason, call tools, use context, remember state, or trigger workflow actions stays inside the boundaries the business expects. The test target is the full operating loop: user input, system instructions, retrieval, tool selection, approval behavior, external APIs, memory writes, and final action.</li><li><strong>What makes agents different from normal applications</strong> — Traditional applications usually follow explicit code paths. Agents often choose a path at runtime based on prompts, retrieved documents, tool descriptions, memory, and model judgment. That makes them useful, but it also creates new security questions: which tools can the agent call, what data can it see, what instructions can override the task, and how does it behave when sources conflict?</li><li><strong>Core attack surfaces to include</strong> — A practical test covers direct prompts, indirect prompts hidden in retrieved content, tool descriptions, browser pages, files, memory, API responses, role boundaries, approval gates, and any system that receives agent output. For coding or operations agents, the scope should include shell commands, repositories, tickets, cloud consoles, secrets, and deployment workflows.</li><li><strong>What a practical assessment includes</strong> — The assessment should begin with an agent map: tools, permissions, data sources, users, environments, and approval requirements. It should then run adversarial scenarios that test prompt hierarchy, retrieval trust, tool selection, authorization, memory persistence, sensitive-data handling, output validation, and recovery behavior. Strong tests are repeatable and tied to business impact.</li><li><strong>Evidence and deliverables</strong> — Good deliverables include the agent map, tested scenarios, reproduced failures, affected tools or data, screenshots or logs, risk ratings, reproduction notes, fix guidance, and retest criteria. The report should separate confirmed exploit paths from rejected attempts, blocked paths, and theoretical risks that could not be proven inside the approved scope.</li><li><strong>When to test an AI agent</strong> — Test before production, after adding new tools, after changing model behavior, before expanding permissions, after connecting sensitive data, and before giving agents write access. Also retest after incidents, major prompt changes, retrieval-source changes, and policy updates. Lightweight tests can run continuously; deeper red-team work should happen before major autonomy increases.</li><li><strong>How agent testing differs from model evaluation</strong> — Model evaluation usually measures whether a model behaves well across a dataset or benchmark. Agent security testing measures whether the product workflow remains safe when the model has context, memory, tools, permissions, and business objectives. The same model can be low risk in a chat-only feature and high risk when connected to code, payments, support actions, or production data.</li><li><strong>A minimum test plan for teams starting now</strong> — A small team can start with a focused plan: map the agent, list high-impact tools, mark sensitive data sources, create five realistic misuse missions, capture full traces, and retest after each fix. Include at least one direct prompt case, one indirect retrieval case, one authorization case, one tool misuse case, and one memory or persistence case.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>AI Red Teaming vs Traditional Pentesting</title>
      <link>https://loki-intelligence.com/blog/ai-red-teaming-vs-traditional-pentesting</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/ai-red-teaming-vs-traditional-pentesting</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>AI red teaming and traditional pentesting solve different security questions. Learn when to use each and how they work together.</description>
      <content:encoded><![CDATA[<p>AI red teaming and traditional penetration testing are complementary, but they are not the same engagement. A traditional pentest usually focuses on technical weaknesses in applications, networks, cloud services, APIs, authentication, and infrastructure. AI red teaming focuses on whether an AI system can be pushed into unsafe behavior across prompts, tools, memory, policies, data boundaries, and workflows. The difference matters because AI failures are often behavioral and contextual. A system can pass a normal web test and still let an agent leak data, misuse a tool, ignore a policy, or act with more authority than the business intended.</p><ul><li><strong>The short version</strong> — Traditional pentesting asks whether an attacker can exploit software, infrastructure, or configuration weaknesses. AI red teaming asks whether an AI system can be manipulated into unsafe decisions or actions. The first is usually about technical control failure. The second is about model behavior, context trust, tool authority, and policy enforcement under pressure.</li><li><strong>What traditional pentesting covers well</strong> — A traditional pentest is strong for web vulnerabilities, broken access control, authentication flaws, API abuse, injection, exposed services, cloud misconfiguration, weak secrets handling, and business-logic issues in deterministic workflows. It usually produces clear reproduction steps, affected assets, impact, severity, and remediation guidance.</li><li><strong>What AI red teaming covers well</strong> — AI red teaming is useful for prompt injection, jailbreak resistance, indirect prompt attacks, tool misuse, data leakage, model overreach, unsafe autonomy, memory poisoning, retrieval poisoning, policy bypass, and harmful output in the product's real context. The best tests use missions, not isolated prompts, because agents fail across steps.</li><li><strong>The biggest difference is evidence</strong> — Pentest evidence often shows a request, response, payload, permission flaw, or data access path. AI red-team evidence should show the full decision trace: prompt, retrieved context, tool list, tool call, approval state, memory change, final response, and business impact. Without the trace, the team cannot tell whether the fix should be prompt design, permission design, tool design, or workflow design.</li><li><strong>When you need both</strong> — You need both when an AI feature can access customer data, call internal APIs, browse the web, write to systems, create tickets, run code, change configurations, summarize sensitive records, or influence financial or operational decisions. The underlying app may have classic vulnerabilities, while the agent layer may create new paths through legitimate permissions.</li><li><strong>How to scope the engagement</strong> — Start by listing the product surfaces, AI features, models, prompts, tools, APIs, retrieval sources, memory stores, user roles, and environments. Decide which actions are safe to test in production and which need a staging environment. Define success criteria for both classic vulnerabilities and AI-specific failures.</li><li><strong>What deliverables should look like</strong> — A traditional pentest report should list validated vulnerabilities, reproduction steps, affected assets, severity, and remediation. An AI red-team report should also include scenario goals, prompt hierarchy, retrieved context, model decisions, tool calls, approvals, memory changes, blocked attempts, and the final business impact. Both reports should be concise enough for leadership and specific enough for engineering.</li><li><strong>How often to run each test type</strong> — Run lightweight automated checks continuously, run traditional pentests around major releases or annually for assurance, and run AI red-team work whenever an agent gains new tools, memory, data access, or autonomy. For high-impact agents, keep a regression suite of previous failures and rerun it whenever prompts, models, tools, or policies change.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>MCP Security Testing Checklist</title>
      <link>https://loki-intelligence.com/blog/mcp-security-testing-checklist</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/mcp-security-testing-checklist</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>A practical MCP security checklist for testing tools, authorization, prompts, data access, secrets, logging, and agent workflows.</description>
      <content:encoded><![CDATA[<p>Model Context Protocol, or MCP, gives AI applications a standard way to connect with tools, data sources, and services. That makes MCP useful for enterprise agents, developer tools, support workflows, and internal automation. It also creates a security boundary that must be tested. An MCP server can expose sensitive resources, powerful tools, misleading tool descriptions, broad OAuth scopes, or unsafe actions through a friendly interface. This checklist helps teams test MCP implementations before they become a hidden path from prompt to production impact.</p><ul><li><strong>Inventory every MCP server, tool, and resource</strong> — Start with a complete inventory. List every MCP server, transport, exposed tool, resource, prompt template, connected API, backing service, environment, and owner. Record which tools are read-only, which can modify state, which can access secrets, and which can reach customer, financial, production, or internal data.</li><li><strong>Test authorization and scope boundaries</strong> — Verify how users authenticate, how consent is granted, how tokens are issued, how scopes map to tools, and whether one user can influence another user's connected resources. For HTTP transports, review the authorization flow, token audience, redirect handling, session binding, revocation, and whether a tool can be called outside the intended user context.</li><li><strong>Review tool descriptions as prompt surface</strong> — Tool names, descriptions, schemas, examples, and errors are not just documentation. They become model context. Test whether malicious or confusing descriptions can cause the agent to choose a dangerous tool, leak data, ignore user intent, or treat tool-provided text as a higher-priority instruction.</li><li><strong>Exercise read, write, and destructive actions separately</strong> — Separate tools into read-only, low-impact write, sensitive write, and destructive actions. Test whether the agent can call each class directly, indirectly, repeatedly, or through ambiguous user intent. Sensitive actions should require confirmation, clear target display, policy checks, logging, and in many cases a human approval gate.</li><li><strong>Check secrets, files, and data minimization</strong> — Test whether tools expose secrets, environment variables, credentials, internal file paths, customer records, system prompts, hidden notes, logs, or oversized data blobs. Limit returned fields, redact sensitive values, enforce resource-level access control, and make sure tool outputs do not include data the model does not need for the task.</li><li><strong>Verify logging, replay, and incident response</strong> — Log the user, agent, MCP server, tool, arguments, resource identifiers, approval state, result status, and correlation ID for each meaningful call. Test whether security teams can replay a suspicious chain, revoke tokens, disable a tool, rotate affected secrets, and determine which data was exposed.</li><li><strong>Validate client-side MCP behavior</strong> — The MCP client should clearly present connected servers, tool permissions, sensitive actions, and approval prompts. Test whether the client distinguishes trusted instructions from tool output, warns before high-impact actions, prevents silent server changes, and gives users a way to disconnect or revoke access. Also test how the client behaves when a server returns malformed, oversized, or hostile content.</li><li><strong>Validate server-side MCP controls</strong> — The MCP server should enforce authorization before every tool call, validate arguments, reject unexpected resources, minimize returned data, rate-limit sensitive operations, and keep durable audit logs. Test negative cases, not only happy paths. A tool should fail safely when the agent asks for a resource, action, or field outside the user's approved scope.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Prompt Injection Testing Guide</title>
      <link>https://loki-intelligence.com/blog/prompt-injection-testing-guide</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/prompt-injection-testing-guide</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>A practical guide to prompt injection testing for AI apps, agents, retrieval systems, tool use, memory, and workflow boundaries.</description>
      <content:encoded><![CDATA[<p>Prompt injection testing checks whether untrusted text can override, confuse, or redirect an AI system away from the developer's intended behavior. The risk is broader than jailbreak prompts in a chat box. Modern AI products read documents, websites, tickets, emails, tool outputs, logs, and memory. Any of those inputs can carry instructions that the model may treat as relevant context. A good test program uses safe, controlled scenarios to verify instruction hierarchy, data boundaries, tool permissions, output handling, and recovery behavior without publishing exploit playbooks or relying on one-off prompt tricks.</p><ul><li><strong>Define what prompt injection means for your product</strong> — Start by defining the expected instruction hierarchy: system instructions, developer policy, user intent, retrieved content, tool output, and memory. Prompt injection testing asks whether lower-trust content can override higher-trust instructions or cause the system to reveal, change, or do something outside the intended task.</li><li><strong>Test direct and indirect injection</strong> — Direct injection comes from the user prompt. Indirect injection comes from content the system retrieves or reads on behalf of the user, such as documents, pages, tickets, email, code comments, calendar entries, or tool responses. The test plan should include both, because many real failures happen when the user never sees the malicious instruction directly.</li><li><strong>Use missions instead of magic phrases</strong> — Do not judge security by whether one famous jailbreak phrase works. Build missions that represent realistic product tasks: summarize a hostile document, triage a support case, prepare a code change, search internal data, or decide whether to call a tool. Measure whether the system follows the right authority and preserves boundaries across the full workflow.</li><li><strong>Check tool and data boundaries</strong> — For tool-using systems, test whether injected instructions can change tool selection, arguments, target resources, approval behavior, or output destination. For data-heavy systems, test whether injected content can make the model reveal hidden context, retrieve unrelated records, include secrets, or combine data across users or tenants.</li><li><strong>Evaluate mitigations with retests</strong> — Common mitigations include strict tool permissions, retrieval filtering, context labeling, output validation, allowlisted actions, confirmation gates, data minimization, model-independent policy checks, and logging. Retest each mitigation against the original mission and nearby variants to make sure the fix addresses the trust boundary, not just one prompt.</li><li><strong>What evidence to keep</strong> — Keep the test mission, trusted instructions, untrusted input, retrieved snippets, model response, tool calls, approvals, data returned, logs, and final impact. Mark whether the path was confirmed, blocked, partially successful, or theoretical. Avoid storing sensitive secrets in the report unless they are redacted and necessary to prove impact.</li><li><strong>Common failure patterns to watch</strong> — Common failures include treating retrieved text as instructions, revealing hidden prompts, summarizing malicious content as trusted fact, calling tools with attacker-selected arguments, copying secrets into output, accepting tool responses as policy, and storing hostile instructions in memory. Track the pattern, not only the exact text that triggered it.</li><li><strong>Turn prompt tests into regression cases</strong> — Every confirmed prompt injection path should become a regression case with a mission, trusted context, untrusted context, expected safe behavior, and required logs. Rerun those cases when prompts, models, retrieval sources, tools, permissions, or memory behavior changes. Keep the cases safe and focused on boundary validation rather than public exploit text.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>How to Evaluate an AI Security Testing Provider</title>
      <link>https://loki-intelligence.com/blog/how-to-evaluate-ai-security-testing-provider</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/how-to-evaluate-ai-security-testing-provider</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>Use this buyer guide to evaluate AI security testing providers by scope, methodology, evidence, safety, reporting, and retesting.</description>
      <content:encoded><![CDATA[<p>Choosing an AI security testing provider is difficult because the market mixes traditional pentesting, model evaluation, AI safety research, compliance consulting, automated scanning, and red-team services under similar labels. The right provider should understand both software security and AI-specific failure modes. They should be able to test prompts, tools, retrieval, memory, authorization, data access, and workflow impact without turning the engagement into theater. Use this guide to compare providers on the things that matter: scope quality, methodology, evidence, safety controls, reporting, remediation, and retesting. The buyer should leave with confidence that findings will become fixes.</p><ul><li><strong>Start with the systems they can actually test</strong> — Ask whether the provider can test your real architecture: chat interface, agent tools, APIs, retrieval, vector stores, memory, model gateway, cloud services, authentication, CI/CD, logging, and production workflow boundaries. A provider that only tests standalone prompts may miss the risks that matter most to your product.</li><li><strong>Ask for a methodology, not a vibe</strong> — A credible provider should explain how they map the system, select scenarios, test instruction hierarchy, evaluate tool use, verify data leakage, measure approval behavior, and separate confirmed findings from noise. They should also describe what they will not test without explicit authorization.</li><li><strong>Demand reproducible evidence</strong> — Ask to see a sample report structure. Strong reports include scenario description, affected component, trace, tool calls, data accessed, business impact, severity rationale, screenshots or logs, remediation guidance, and retest criteria. They should avoid vague claims like the model was jailbreakable without explaining the real impact.</li><li><strong>Check production safety controls</strong> — A provider should be clear about safe testing boundaries: rate limits, prohibited actions, staging versus production, test accounts, data handling, destructive actions, payment flows, customer-impacting workflows, and emergency stop conditions. They should document authorization before testing begins.</li><li><strong>Look for remediation that engineers can ship</strong> — Good remediation is specific. It may recommend narrower tool scopes, approval gates, data minimization, retrieval labeling, output validation, policy checks outside the model, memory controls, better logging, or API authorization changes. The provider should connect each recommendation to the failed path it fixes.</li><li><strong>Make retesting part of the purchase</strong> — Ask whether retesting is included, how long it remains available, and what evidence will close a finding. Retesting should run the original scenario and reasonable variants after the fix. For agent systems, retesting should also check whether the change created new behavior in nearby workflows.</li><li><strong>Questions to ask on a vendor call</strong> — Ask which AI attack classes they test, how they handle tool-using agents, whether they can test authenticated workflows, how they avoid unsafe production impact, what evidence appears in the report, how retesting works, and how they separate model behavior from application security. Ask for examples of fixes they have recommended, not only examples of prompts they have tried.</li><li><strong>Warning signs when comparing providers</strong> — Be careful with providers that promise universal AI safety, rely only on prompt lists, cannot test tools or APIs, avoid discussing production boundaries, provide no sample evidence, skip retesting, or treat every model refusal bypass as a critical issue. Also be careful when a report cannot distinguish confirmed business impact from theoretical concern.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Cloud Pentest Checklist for SaaS Teams</title>
      <link>https://loki-intelligence.com/blog/cloud-pentest-checklist-for-saas-teams</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/cloud-pentest-checklist-for-saas-teams</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>A cloud pentest checklist for SaaS teams covering exposure, identity, APIs, storage, secrets, CI/CD, monitoring, and retesting.</description>
      <content:encoded><![CDATA[<p>A cloud pentest for a SaaS company should answer one practical question: what could an attacker chain from the public surface into customer data, control-plane access, sensitive infrastructure, or business impact? Cloud testing is not just a port scan, and it is not only a configuration review. The strongest assessments combine external exposure, identity, APIs, storage, secrets, workloads, CI/CD, logging, and product-specific workflows. This checklist helps SaaS teams prepare a useful scope and understand what good evidence should look like. It is written for teams that need practical coverage without slowing normal product delivery. Use it before kickoff, during remediation, and again when cloud architecture changes across accounts and environments.</p><ul><li><strong>Map internet-facing exposure first</strong> — Start with domains, subdomains, APIs, load balancers, edge services, storage endpoints, admin panels, staging systems, documentation portals, and third-party integrations. Confirm what is intentionally public, what is forgotten, and what should be restricted behind identity, VPN, allowlists, or private networking.</li><li><strong>Review identity and access paths</strong> — Test authentication, authorization, tenant separation, service accounts, IAM roles, cross-account access, admin workflows, support impersonation, SSO, OAuth apps, and privilege escalation paths. For SaaS products, include both product identity and cloud identity, because real incidents often cross that boundary.</li><li><strong>Test APIs and business workflows</strong> — Include REST, GraphQL, webhooks, background jobs, file uploads, exports, billing flows, invitation flows, integrations, and admin APIs. Test broken object-level authorization, excessive data exposure, insecure state changes, rate limits, replay behavior, and whether tenant identifiers can be tampered with.</li><li><strong>Inspect storage, secrets, and data movement</strong> — Review object storage, databases, backups, logs, queues, caches, analytics pipelines, secrets managers, environment variables, build artifacts, and data exports. Test whether sensitive data is public, over-shared, retained too long, copied into logs, or reachable by workloads that do not need it.</li><li><strong>Include CI/CD and deployment permissions</strong> — Assess source control, CI runners, deployment tokens, container registries, artifact stores, infrastructure-as-code permissions, branch protections, environment approvals, and secret exposure in pipelines. Validate whether a compromised developer account or build job could alter production infrastructure or read sensitive cloud credentials.</li><li><strong>Define evidence, safety, and retest criteria</strong> — Before testing begins, define safe proof methods, prohibited actions, test accounts, maintenance windows, data-handling rules, severity expectations, and retest requirements. Evidence should show the asset, path, permission, data accessed, impact, and recommended fix without causing unnecessary production change.</li><li><strong>What to prepare before the cloud pentest</strong> — Prepare domains, cloud accounts in scope, known exclusions, test users, role descriptions, API documentation, architecture diagrams, safe testing windows, escalation contacts, and a list of actions that must not be performed. If staging differs from production, explain the differences so testers do not draw the wrong conclusion from a safer environment.</li><li><strong>Turn findings into cloud controls</strong> — After the test, convert findings into durable controls: stricter IAM, better tenant checks, storage policies, secret rotation, CI/CD approvals, logging alerts, infrastructure-as-code rules, and regression tests. Assign owners and closure evidence for each fix. Retest the original path and any nearby path that the fix could affect.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Automated Vulnerability Assessment vs Manual Pentest</title>
      <link>https://loki-intelligence.com/blog/automated-vulnerability-assessment-vs-manual-pentest</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/automated-vulnerability-assessment-vs-manual-pentest</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>Compare automated vulnerability assessment and manual pentesting: speed, depth, evidence, limitations, and when to combine both.</description>
      <content:encoded><![CDATA[<p>Automated vulnerability assessment and manual penetration testing are both useful, but they answer different questions. Automation is best for broad, repeatable coverage: exposed services, known vulnerabilities, missing headers, outdated software, common misconfigurations, and regression checks. Manual pentesting is best for context, chaining, authorization, business logic, exploit validation, and evidence that explains real impact. Mature security programs use both. Automation finds and tracks the obvious issues quickly. Manual testing proves whether the important paths are actually exploitable and worth prioritizing. The best result is a repeatable security loop that improves after every release.</p><ul><li><strong>What automated vulnerability assessment does well</strong> — Automated assessment is useful for frequent checks across many assets. It can identify known CVEs, exposed ports, TLS problems, security-header gaps, dependency issues, common web weaknesses, cloud exposure, and drift from expected configuration. It is fast, consistent, and good for watching change over time.</li><li><strong>Where automation falls short</strong> — Automation struggles with business context, multi-step authorization, tenant isolation, chained impact, unusual workflows, product-specific logic, and whether a finding is actually exploitable in your environment. It can also create false positives, miss authenticated paths, or rank low-impact issues above risks that matter more to the business.</li><li><strong>What manual pentesting adds</strong> — Manual pentesting adds hypothesis, creativity, context, and impact validation. A tester can chain weak controls, compare roles, inspect business workflows, review API behavior, test tenant boundaries, use realistic accounts, and stop before unsafe production impact. The output should be fewer findings with stronger evidence.</li><li><strong>The best programs combine both</strong> — Use automation continuously for coverage and drift detection. Use manual testing for high-risk releases, new product surfaces, authentication changes, payment or admin workflows, cloud architecture changes, AI agent capabilities, and customer-facing assurance. Feed manual findings back into automated regression checks where possible.</li><li><strong>How reports should differ</strong> — Automated reports should prioritize ownership, asset, evidence, scanner confidence, severity, affected versions, and remediation status. Manual reports should include scenario, reproduction context, business impact, exploitability, affected roles, proof, recommended fix, and retest criteria. Both should avoid dumping long lists without prioritization.</li><li><strong>When to choose each option</strong> — Choose automated assessment when you need broad recurring coverage, launch checks, hygiene monitoring, and fast feedback on known issue classes. Choose manual pentesting when you need confidence in critical workflows, compliance evidence, customer assurance, complex authorization, cloud attack-chain analysis, or AI agent behavior.</li><li><strong>Use automation before the manual test</strong> — Run automated checks before a manual pentest to clean up obvious issues, confirm scope, identify exposed assets, collect version data, and highlight areas that deserve deeper review. Share the automation output with testers so they can spend less time on hygiene and more time validating chains, authorization, and business impact.</li><li><strong>Close the loop after testing</strong> — After a manual finding is fixed, add an automated check when the condition is measurable. That might be a configuration rule, dependency alert, API authorization test, cloud policy check, or regression scenario. Keep manual retesting for complex workflows where automation cannot safely prove impact on its own.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Kernel Risk, Supply Chain Malware, and Phishing Kits</title>
      <link>https://loki-intelligence.com/blog/2026-07-04</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-04</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <description>Key cyber updates for July 4 covering Linux privilege escalation, embedded device flaws, npm threats, proxy botnets, and Microsoft 365 phishing.</description>
      <content:encoded><![CDATA[<p>Today’s reporting highlights risk across core infrastructure, developer ecosystems, and identity platforms. Teams should prioritize patch visibility, dependency controls, phishing resistance, and monitoring for compromised edge and consumer-linked devices.</p><ul><li><strong>New &quot;Bad Epoll&quot; Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android</strong> — A Linux kernel vulnerability dubbed Bad Epoll can allow local unprivileged users to gain root-level control, with impact spanning servers, desktops, and Android-based systems. Fixes are reportedly available.</li><li><strong>New Avalon Malware Framework Packs CrownX Ransomware Capabilities</strong> — Researchers identified Avalon, a modular malware framework delivered through phishing and designed to combine credential theft, remote access, movement across environments, and ransomware-like disruption.</li><li><strong>Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices</strong> — Seven vulnerabilities were disclosed in FatFs, a lightweight filesystem library widely used in embedded products to handle FAT and exFAT storage media. The findings may affect many devices because the component is broadly bundled into firmware.</li><li><strong>NetNut proxy network disrupted, 2 million infected devices cut off</strong> — A coordinated disruption involving Google reportedly severed NetNut’s access to around two million compromised Android devices used in a residential proxy network. Affected devices included smart TVs and streaming hardware.</li><li><strong>North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets</strong> — North Korea-linked actors were tied to malicious npm packages impersonating Rollup-related polyfill tooling, with the goal of enabling access and stealing developer secrets.</li><li><strong>ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit</strong> — A phishing-as-a-service platform called ARToken appears connected to EvilTokens and exposes tooling focused on Microsoft 365 credential and session theft campaigns.</li><li><strong>Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer</strong> — A newly described actor, Armored Likho, has been linked to campaigns against government and power-sector organizations in Russia, Brazil, and Kazakhstan, using a stealer known as BusySnake.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Brief: Ransomware Access Paths, Secret Cleanup, and IoT Exposure</title>
      <link>https://loki-intelligence.com/blog/2026-07-03</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-03</guid>
      <pubDate>Fri, 03 Jul 2026 06:00:00 GMT</pubDate>
      <description>Ransomware crews lean on exposed apps, AI-assisted operations, fake PoCs, and credential sprawl while defenders face KEV and IoT patch pressure.</description>
      <content:encoded><![CDATA[<p>Today’s risk theme is operational exposure: unpatched edge systems, leaked credentials, and trusted developer workflows are being used to accelerate compromise. Teams should prioritize KEV-driven patching, secret remediation at scale, tighter third-party access controls, and safer handling of public exploit code.</p><ul><li><strong>Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials</strong> — Ransomware affiliates linked to Anubis are reportedly abusing Citrix Bleed 2 for initial access while also using legitimate remote management tools, vulnerable drivers, and supply chain credentials to move through environments.</li><li><strong>AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack</strong> — Researchers describe a ransomware incident where an AI agent allegedly automated much of the intrusion lifecycle after abusing a Langflow remote code execution flaw.</li><li><strong>New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos</strong> — A malware campaign dubbed ChocoPoC is targeting vulnerability researchers with fake GitHub proof-of-concept repositories that install a data-stealing remote access trojan.</li><li><strong>Gardyn IoT Hub</strong> — CISA warns that several Gardyn IoT Hub components contain vulnerabilities that could let unauthenticated users access or control managed devices.</li><li><strong>ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories</strong> — This roundup highlights a broad set of current issues, including AI compute abuse, email security weaknesses, ransomware activity, browser risks, bot activity, and sandbox gaps.</li><li><strong>SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation</strong> — CISA added Microsoft SharePoint Server CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild.</li><li><strong>How GitHub used secret scanning to reach inbox zero</strong> — GitHub shared how it reduced more than 20,000 secret scanning alerts across 15,000 repositories by separating high-value findings from noise and building repeatable remediation workflows.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Exploited Enterprise, AI, and ICS Flaws</title>
      <link>https://loki-intelligence.com/blog/2026-07-01</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-07-01</guid>
      <pubDate>Wed, 01 Jul 2026 06:00:00 GMT</pubDate>
      <description>Active exploitation hit AI apps, remote support, Oracle payments, Windows security tooling, and SCADA/HMI systems.</description>
      <content:encoded><![CDATA[<p>Attackers are moving quickly on newly disclosed flaws in internet-facing business platforms, with activity ranging from cryptomining to ransomware and data theft. AI agent ecosystems also remain a growing risk area as researchers show how tool metadata and command handling can be abused.</p><ul><li><strong>Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints</strong> — Exposed Langflow instances are being targeted through a critical unauthenticated remote code execution flaw to install Monero mining malware. The activity highlights continued attacker interest in AI application infrastructure left reachable from the internet.</li><li><strong>Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer</strong> — A critical SimpleHelp authentication vulnerability is being exploited to deliver newly reported malware families known as TaskWeaver and Djinn Stealer. Remote support tools remain high-value targets because they often provide broad access into managed environments.</li><li><strong>Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild</strong> — A critical Oracle E-Business Suite vulnerability affecting Oracle Payments is reportedly under active exploitation. The issue involves authentication and privilege management weaknesses in a high-value enterprise financial platform.</li><li><strong>Frangoteam FUXA SCADA/HMI</strong> — CISA warned that affected Frangoteam FUXA SCADA/HMI deployments can expose user and role information to unauthenticated remote attackers. The issue affects versions up to and including 1.3.1.</li><li><strong>Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data</strong> — Microsoft research warns that malicious Model Context Protocol tool descriptions can influence AI agents into leaking enterprise data. The risk comes from agents trusting tool metadata while acting with user-granted permissions.</li><li><strong>GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks</strong> — Research on GuardFall shows that AI coding agents can still be exposed to long-known shell injection patterns despite safety checks. The findings reinforce that agent guardrails should not be treated as a substitute for secure execution design.</li><li><strong>CISA: Windows BlueHammer flaw now exploited by ransomware gangs</strong> — CISA says ransomware groups are exploiting the Windows BlueHammer privilege escalation flaw affecting Microsoft Defender. The vulnerability has a history of zero-day abuse and is now tied to ransomware operations.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Daily Security Brief: Exploited Enterprise Apps and Appliance Bugs</title>
      <link>https://loki-intelligence.com/blog/2026-06-30</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-06-30</guid>
      <pubDate>Tue, 30 Jun 2026 06:00:00 GMT</pubDate>
      <description>Active exploitation hit Oracle EBS, SimpleHelp, Windows Defender, and network appliances, raising patching urgency for product and IT teams.</description>
      <content:encoded><![CDATA[<p>Today’s risk picture is dominated by actively exploited flaws in business-critical software, remote support tools, endpoint security, and edge appliances. Teams should prioritize exposed systems, confirm patch status, and tighten monitoring around admin and finance platforms.</p><ul><li><strong>CISA Adds One Known Exploited Vulnerability to Catalog</strong> — CISA added CVE-2026-48558, a SimpleHelp authentication bypass issue, to its Known Exploited Vulnerabilities catalog after confirming active abuse.</li><li><strong>Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild</strong> — The Hacker News reports that CVE-2026-46817 in Oracle E-Business Suite is being exploited, affecting Oracle Payments through authentication and privilege management weaknesses.</li><li><strong>Hackers now exploit critical Oracle E-Business flaw in attacks</strong> — BleepingComputer also covers active attacks targeting the critical Oracle E-Business Suite flaw, citing threat intelligence that exploitation has started in the wild.</li><li><strong>Inside the Advisory Database and what happens when vulnerability volume breaks records</strong> — GitHub Security describes the growing volume of vulnerability reports handled by its Advisory Database and the pressure this creates for maintainers and security teams.</li><li><strong>CISA: Windows BlueHammer flaw now exploited by ransomware gangs</strong> — BleepingComputer reports that CISA confirmed ransomware groups are exploiting the Windows Defender privilege escalation flaw known as BlueHammer.</li><li><strong>Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth</strong> — The Hacker News reports a critical Progress Kemp LoadMaster vulnerability that could allow unauthenticated command execution with root-level impact on affected appliances.</li><li><strong>Critical SimpleHelp flaw exploited to deploy new stealer malware</strong> — BleepingComputer reports that attackers are exploiting the SimpleHelp flaw to distribute newly observed stealer malware across Windows, macOS, and Linux systems.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Agentic Harnesses: The Control Room for AI Security Testing</title>
      <link>https://loki-intelligence.com/blog/2026-06-29</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-06-29</guid>
      <pubDate>Mon, 29 Jun 2026 06:00:00 GMT</pubDate>
      <description>Agentic harnesses turn unpredictable AI workflows into observable, repeatable, security-testable systems.</description>
      <content:encoded><![CDATA[<p>Agentic systems do not fail like normal software: they improvise, chain tools, mutate context, and create risk across steps. A strong harness gives teams the control room they need to observe every decision, replay failures, and turn agent behavior into security evidence.</p><ul><li><strong>A harness is the flight recorder for agent behavior</strong> — A serious agentic harness captures prompts, model outputs, tool calls, retrieved context, approvals, denials, memory writes, and final actions as one linked trace.</li><li><strong>Tool calls are the blast radius</strong> — The dangerous part of an AI agent is rarely the sentence it writes. The dangerous part is the action it can take through tools, APIs, browsers, shells, tickets, email, and data stores.</li><li><strong>Replay is where security becomes engineering</strong> — When an agent makes a risky decision once, the harness should preserve the full scenario so the team can replay it against new prompts, policies, models, and tool configurations.</li><li><strong>The best harnesses separate autonomy into lanes</strong> — Not every agent action deserves the same freedom. Read-only analysis, low-risk drafting, customer-visible changes, production writes, and security-sensitive actions should run through different lanes.</li><li><strong>Scoring must measure decisions, not just outputs</strong> — A flashy answer can hide a risky path. Agentic harnesses should score whether the agent chose the right tools, respected boundaries, handled uncertainty, and stopped when confidence was low.</li></ul>]]></content:encoded>
    </item>
    <item>
      <title>Flash Harnesses: Red-Team Loops for Agentic AI</title>
      <link>https://loki-intelligence.com/blog/2026-06-28</link>
      <guid isPermaLink="true">https://loki-intelligence.com/blog/2026-06-28</guid>
      <pubDate>Sun, 28 Jun 2026 06:00:00 GMT</pubDate>
      <description>A high-signal agentic harness should feel like a security cockpit: fast scenarios, sharp telemetry, and no room for mystery failures.</description>
      <content:encoded><![CDATA[<p>The next generation of AI security testing will not be a prompt spreadsheet. It will be a flash harness: a compact red-team loop that throws realistic pressure at an agent, records the full decision chain, and turns unsafe behavior into repeatable tests.</p><ul><li><strong>Start with missions, not prompts</strong> — A prompt only tests one input. A mission tests the full agent workflow: objective, context, tools, constraints, user pressure, policy boundaries, and final decision.</li><li><strong>Inject pressure without handing over exploit steps</strong> — Flash harnesses should simulate urgency, ambiguity, conflicting instructions, sensitive data requests, and tool misuse attempts without publishing procedural abuse playbooks.</li><li><strong>Every approval gate should emit a signal</strong> — When an agent asks for human approval, skips approval, or gets denied, the harness should preserve the reason, context, tool target, and downstream outcome.</li><li><strong>Memory is a live attack surface</strong> — Agent memory can preserve preferences, instructions, retrieved facts, user history, and operational context. That makes it useful, but also worth testing like a stateful security boundary.</li><li><strong>Ship the kill switch before the demo gets loud</strong> — The harness should prove that teams can pause an agent, revoke a tool, roll back a risky path, and preserve evidence without improvising during an incident.</li></ul>]]></content:encoded>
    </item>
  </channel>
</rss>
