SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, September 19, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical Orkes Conductor RCE Vulnerability Actively Exploited | CRITICAL |
|
5 C2 IPs | 86 OTX IOCs | 33 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by critical vulnerabilities in enterprise infrastructure, including a CVSS 10.0 privilege escalation flaw in Microsoft Azure AI Foundry (CVE-2026-85889) and an actively exploited RCE in Orkes Conductor (CVE-2026-58138). Concurrently, threat actors like Transparent Tribe are deploying novel Rust backdoors via private GitHub repositories, while the North Korean "WaterPlum" campaign targets cryptocurrency assets globally. Supply chain risks also surged, highlighted by a breach of Brevo's API keys injecting malware into over 100,000 websites and malicious npm packages distributing the "WeaselBiscuit" stealer. |
|
■ CRITICAL STORIES Critical Orkes Conductor Vulnerability Exploited in Attacks CVE-2026-58138 allows unauthenticated remote code execution via inline workflow definitions and is actively being exploited in the wild, posing an immediate threat to orchestration pipelines. |
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation Tracked as CVE-2026-85889, this maximum-severity vulnerability allowed unauthorized privilege escalation in Azure AI Foundry, highlighting the growing attack surface of enterprise AI deployments. |
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Attackers leveraged a compromised API key to deploy a malicious Cloudflare worker, demonstrating how easily supply chain vectors can be weaponized to distribute malware at scale. |
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign The FBI and international allies warned of a widespread campaign targeting job applicants to steal cryptocurrency, showing the persistent threat of DPRK-aligned financial cybercrime. |
|
■ CVEs IDENTIFIED CVE-2026-85889 Microsoft Azure AI Foundry — Unauthorized Privilege Escalation |
CVE-2026-58138 Orkes Conductor — Unauthenticated Remote Code Execution via inline workflow definitions |
[CVE-TBD] Linux Kernel — Local Privilege Escalation to Root |
[CVE-TBD] WordPress Core — Click2Shell forced theme installation leading to Remote Code Execution |
|
■ THREAT ACTORS Transparent Tribe (APT36 / Earth Karkaddan) | APT |
Deploying a new Rust backdoor using private GitHub repositories for C2 targeting government and defense entities in India and Afghanistan. |
WaterPlum (DPRK) | State-Sponsored |
Target job applicants across 100 countries to infect devices and steal cryptocurrency. |
NightEagle | APT / Cyberespionage |
Targeting China's high-tech sector and expanding operations into Russian businesses. |
|
|
|
■ ATT&CK TTPs | T1068 | | Exploitation for Privilege Escalation | Linux kernel local root exploits and Azure AI Foundry CVE-2026-85889. |
| T1190 | | Exploit Public-Facing Application | Orkes Conductor CVE-2026-58138 RCE and Gyazo server vulnerability. |
| T1195.002 | | Malicious Software Update | Brevo supply chain attack injecting scripts via compromised API. |
| T1584.005 | | Botnet | NightmareStresser DDoS-for-hire service disruption. |
| T1204.001 | | User Execution: Malicious Link | WordPress Click2Shell flaw requiring admin to click a link. |
| T1102.002 | | Web Service: Bidirectional Communication | Transparent Tribe using private GitHub repositories for C2. |
|
■ PATCH PRIORITY Orkes Conductor — Unauthenticated RCE (CVE-2026-58138) actively exploited in the wild — SecurityWeek |
Check Point Management Systems — Remote code execution with root privileges — BleepingComputer |
Linux Kernel — Four local root exploits released publicly — The Hacker News |
WordPress Core — Click2Shell flaw chains to code execution — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch immediately: Apply Orkes Conductor updates to remediate CVE-2026-58138 to prevent unauthenticated remote code execution. |
| 2 | [P1] Patch immediately: Apply the latest Check Point Software security updates for management systems to prevent remote code execution with root privileges. |
| 3 | [P1] Patch immediately: Update Linux Kernels to the latest stable versions to patch the four newly disclosed local privilege escalation vulnerabilities. |
| 4 | [P2] Update: Apply WordPress core updates to remediate the Click2Shell vulnerability and prevent unauthorized theme installations. |
| 5 | [P2] Secure: Review default configurations for AWS AgentCore Harness to prevent prompt injection and credential exfiltration. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |