Daily Security Intel

Archives
Log in
Subscribe
September 20, 2026

[SecurityIntel] 20 Sep | Critical Pre-Auth RCE Exploited in Orkes Conductor

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, September 20, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Pre-Auth RCE Exploited in Orkes Conductor

CRITICAL

5

C2 IPs

7

OTX IOCs

12

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by active exploitation of critical remote code execution vulnerabilities in Orkes Conductor (CVE-2026-58138) and SolarWinds Access Rights Manager (CVE-2026-2832). Additionally, emerging risks in AI ecosystems are highlighted by the "BragJack" browser extension hijacking technique and Google Gemini's accidental intrusion into corporate environments. State-sponsored activity also remains high, with North Korea's WaterPlum group compromising over 30,000 devices globally.

■ CRITICAL STORIES

CRITICAL#1

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor, posing an immediate threat to enterprise workflow automation environments.

INFO#2

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds resolved CVE-2026-2832 in its Access Rights Manager (ARM), which allowed unauthenticated attackers to achieve remote code execution via hard-coded cryptographic keys.

INFO#3

North Korean WaterPlum hackers infected 30,000 devices worldwide

A massive campaign by North Korean threat group WaterPlum compromised tens of thousands of devices globally, laundering over $10.7 million in stolen cryptocurrency back to North Korea.

INFO#4

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

A supply chain attack targeting the TanStack npm package enabled threat actors to leverage a former employee's active GitHub credentials, leading to the theft of 170 private repositories.

■ CVEs IDENTIFIED

CVE-2026-58138

Orkes Conductor — Pre-authentication Remote Code Execution (RCE)

Critical

CVE-2026-2832

SolarWinds Access Rights Manager (ARM) — Unauthenticated Remote Code Execution (RCE) via hard-coded key

Critical

[CVE-TBD]

Linux Kernel — Privilege Escalation / Remote Code Execution (CISA KEV)

High

[CVE-TBD]

OpenAI ChatGPT & Codex — Account Takeover via chained flaws

High

■ THREAT ACTORS

WaterPlum

Nation-State (North Korea)

Compromised 30,000 devices globally to steal over $10.7 million in cryptocurrency.

ShinyHunters

Cybercrime / Extortion

Breached and defaced the Clop ransomware Tor leak site, stealing server data and private keys.

Clop

Ransomware-as-a-Service (RaaS)

Had their data leak site hacked and defaced by the ShinyHunters extortion group.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Active exploitation of CVE-2026-58138 in Orkes Conductor and CVE-2026-2832 in SolarWinds ARM.
T1195.002
Supply Chain Compromise: Compromise Software Dependencies | Compromise of the TanStack npm package to target downstream organizations.
T1078
Valid Accounts | Abuse of a former employee's active GitHub account to exfiltrate CrowdSec repositories.
T1176
Browser Extensions | BragJack proof-of-concept malicious browser extension hijacking AI assistants.
T1496
Resource Hijacking | WaterPlum group hijacking 30,000 devices to siphon $10.7 million in cryptocurrency.
T1565
Data Manipulation | ShinyHunters defacing the Clop ransomware leak site.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Orkes Conductor — Pre-auth RCE (CVE-2026-58138) is actively exploited in the wild — THN

[P1 PATCH NOW]≤24h

SolarWinds Access Rights Manager (ARM) — Hard-coded key flaw (CVE-2026-2832) allows unauthenticated RCE — THN

[P1 PATCH NOW]≤24h

Linux Kernel — Three privilege escalation/RCE vulnerabilities are actively exploited in the wild — CISA

[P2 PATCH NOW]≤72h

GitHub Access / Offboarding — Former employee credentials allowed theft of 170 private repositories — THN

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch Orkes Conductor to resolve CVE-2026-58138 to prevent active exploitation of the pre-auth RCE vulnerability.
2[P1] Apply security updates to SolarWinds Access Rights Manager (ARM) to remediate the hard-coded key vulnerability (CVE-2026-2832).
3[P1] Audit and apply patches for the three actively exploited Linux Kernel vulnerabilities recently added to the CISA KEV catalog.
4[P2] Conduct an immediate audit of active GitHub and SaaS credentials, ensuring offboarding processes revoke access for former employees to prevent repository theft.
5[P2] Implement strict extension blocklists in Google Chrome, Microsoft Edge, and Opera to mitigate the risk of BragJack-style AI agent hijacking.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 19 Sep | Critical Orkes Conductor RCE Vulnerability Actively Exploited
Powered by Buttondown, the easiest way to start and grow your newsletter.