SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, September 20, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical Pre-Auth RCE Exploited in Orkes Conductor | CRITICAL |
|
5 C2 IPs | 7 OTX IOCs | 12 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by active exploitation of critical remote code execution vulnerabilities in Orkes Conductor (CVE-2026-58138) and SolarWinds Access Rights Manager (CVE-2026-2832). Additionally, emerging risks in AI ecosystems are highlighted by the "BragJack" browser extension hijacking technique and Google Gemini's accidental intrusion into corporate environments. State-sponsored activity also remains high, with North Korea's WaterPlum group compromising over 30,000 devices globally. |
|
■ CRITICAL STORIES Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor, posing an immediate threat to enterprise workflow automation environments. |
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE SolarWinds resolved CVE-2026-2832 in its Access Rights Manager (ARM), which allowed unauthenticated attackers to achieve remote code execution via hard-coded cryptographic keys. |
North Korean WaterPlum hackers infected 30,000 devices worldwide A massive campaign by North Korean threat group WaterPlum compromised tens of thousands of devices globally, laundering over $10.7 million in stolen cryptocurrency back to North Korea. |
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories A supply chain attack targeting the TanStack npm package enabled threat actors to leverage a former employee's active GitHub credentials, leading to the theft of 170 private repositories. |
|
■ CVEs IDENTIFIED CVE-2026-58138 Orkes Conductor — Pre-authentication Remote Code Execution (RCE) |
CVE-2026-2832 SolarWinds Access Rights Manager (ARM) — Unauthenticated Remote Code Execution (RCE) via hard-coded key |
[CVE-TBD] Linux Kernel — Privilege Escalation / Remote Code Execution (CISA KEV) |
[CVE-TBD] OpenAI ChatGPT & Codex — Account Takeover via chained flaws |
|
■ THREAT ACTORS WaterPlum | Nation-State (North Korea) |
Compromised 30,000 devices globally to steal over $10.7 million in cryptocurrency. |
ShinyHunters | Cybercrime / Extortion |
Breached and defaced the Clop ransomware Tor leak site, stealing server data and private keys. |
Clop | Ransomware-as-a-Service (RaaS) |
Had their data leak site hacked and defaced by the ShinyHunters extortion group. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Active exploitation of CVE-2026-58138 in Orkes Conductor and CVE-2026-2832 in SolarWinds ARM. |
| T1195.002 | | Supply Chain Compromise: Compromise Software Dependencies | Compromise of the TanStack npm package to target downstream organizations. |
| T1078 | | Valid Accounts | Abuse of a former employee's active GitHub account to exfiltrate CrowdSec repositories. |
| T1176 | | Browser Extensions | BragJack proof-of-concept malicious browser extension hijacking AI assistants. |
| T1496 | | Resource Hijacking | WaterPlum group hijacking 30,000 devices to siphon $10.7 million in cryptocurrency. |
| T1565 | | Data Manipulation | ShinyHunters defacing the Clop ransomware leak site. |
|
■ PATCH PRIORITY Orkes Conductor — Pre-auth RCE (CVE-2026-58138) is actively exploited in the wild — THN |
SolarWinds Access Rights Manager (ARM) — Hard-coded key flaw (CVE-2026-2832) allows unauthenticated RCE — THN |
Linux Kernel — Three privilege escalation/RCE vulnerabilities are actively exploited in the wild — CISA |
GitHub Access / Offboarding — Former employee credentials allowed theft of 170 private repositories — THN |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch Orkes Conductor to resolve CVE-2026-58138 to prevent active exploitation of the pre-auth RCE vulnerability. |
| 2 | [P1] Apply security updates to SolarWinds Access Rights Manager (ARM) to remediate the hard-coded key vulnerability (CVE-2026-2832). |
| 3 | [P1] Audit and apply patches for the three actively exploited Linux Kernel vulnerabilities recently added to the CISA KEV catalog. |
| 4 | [P2] Conduct an immediate audit of active GitHub and SaaS credentials, ensuring offboarding processes revoke access for former employees to prevent repository theft. |
| 5 | [P2] Implement strict extension blocklists in Google Chrome, Microsoft Edge, and Opera to mitigate the risk of BragJack-style AI agent hijacking. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |