Daily Security Intel

Archives
Log in
Subscribe
September 19, 2026

[SecurityIntel] 19 Sep | Critical Orkes Conductor RCE Vulnerability Actively Exploited

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, September 19, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Orkes Conductor RCE Vulnerability Actively Exploited

CRITICAL

5

C2 IPs

86

OTX IOCs

33

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by critical vulnerabilities in enterprise infrastructure, including a CVSS 10.0 privilege escalation flaw in Microsoft Azure AI Foundry (CVE-2026-85889) and an actively exploited RCE in Orkes Conductor (CVE-2026-58138). Concurrently, threat actors like Transparent Tribe are deploying novel Rust backdoors via private GitHub repositories, while the North Korean "WaterPlum" campaign targets cryptocurrency assets globally. Supply chain risks also surged, highlighted by a breach of Brevo's API keys injecting malware into over 100,000 websites and malicious npm packages distributing the "WeaselBiscuit" stealer.

■ CRITICAL STORIES

CRITICAL#1

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 allows unauthenticated remote code execution via inline workflow definitions and is actively being exploited in the wild, posing an immediate threat to orchestration pipelines.

CRITICAL#2

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Tracked as CVE-2026-85889, this maximum-severity vulnerability allowed unauthorized privilege escalation in Azure AI Foundry, highlighting the growing attack surface of enterprise AI deployments.

HIGH#3

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Attackers leveraged a compromised API key to deploy a malicious Cloudflare worker, demonstrating how easily supply chain vectors can be weaponized to distribute malware at scale.

HIGH#4

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

The FBI and international allies warned of a widespread campaign targeting job applicants to steal cryptocurrency, showing the persistent threat of DPRK-aligned financial cybercrime.

■ CVEs IDENTIFIED

CVE-2026-85889

Microsoft Azure AI Foundry — Unauthorized Privilege Escalation

Critical (10.0)

CVE-2026-58138

Orkes Conductor — Unauthenticated Remote Code Execution via inline workflow definitions

Critical

[CVE-TBD]

Linux Kernel — Local Privilege Escalation to Root

Critical

[CVE-TBD]

WordPress Core — Click2Shell forced theme installation leading to Remote Code Execution

High

■ THREAT ACTORS

Transparent Tribe (APT36 / Earth Karkaddan)

APT

Deploying a new Rust backdoor using private GitHub repositories for C2 targeting government and defense entities in India and Afghanistan.

WaterPlum (DPRK)

State-Sponsored

Target job applicants across 100 countries to infect devices and steal cryptocurrency.

NightEagle

APT / Cyberespionage

Targeting China's high-tech sector and expanding operations into Russian businesses.

■ ATT&CK TTPs

T1068
Exploitation for Privilege Escalation | Linux kernel local root exploits and Azure AI Foundry CVE-2026-85889.
T1190
Exploit Public-Facing Application | Orkes Conductor CVE-2026-58138 RCE and Gyazo server vulnerability.
T1195.002
Malicious Software Update | Brevo supply chain attack injecting scripts via compromised API.
T1584.005
Botnet | NightmareStresser DDoS-for-hire service disruption.
T1204.001
User Execution: Malicious Link | WordPress Click2Shell flaw requiring admin to click a link.
T1102.002
Web Service: Bidirectional Communication | Transparent Tribe using private GitHub repositories for C2.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Orkes Conductor — Unauthenticated RCE (CVE-2026-58138) actively exploited in the wild — SecurityWeek

[P1 PATCH NOW]≤24h

Check Point Management Systems — Remote code execution with root privileges — BleepingComputer

[P1 PATCH NOW]≤24h

Linux Kernel — Four local root exploits released publicly — The Hacker News

[P2 PATCH NOW]≤72h

WordPress Core — Click2Shell flaw chains to code execution — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch immediately: Apply Orkes Conductor updates to remediate CVE-2026-58138 to prevent unauthenticated remote code execution.
2[P1] Patch immediately: Apply the latest Check Point Software security updates for management systems to prevent remote code execution with root privileges.
3[P1] Patch immediately: Update Linux Kernels to the latest stable versions to patch the four newly disclosed local privilege escalation vulnerabilities.
4[P2] Update: Apply WordPress core updates to remediate the Click2Shell vulnerability and prevent unauthorized theme installations.
5[P2] Secure: Review default configurations for AWS AgentCore Harness to prevent prompt injection and credential exfiltration.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 20 Sep | Critical Pre-Auth RCE Exploited in Orkes Conductor Older → [SecurityIntel] 18 Sep | Active Zero-Day Exploit in Cisco ISE (CVE-2026-76460)
Powered by Buttondown, the easiest way to start and grow your newsletter.