Security news.
Today's cybersecurity landscape is marked by critical vulnerabilities under active exploitation and the increasing involvement of AI in both attacks and defense. Organizations are urged to patch immediately, especially for widely used platforms and core systems like the Linux kernel, while also grappling with the implications of AI's growing role in complex threat chains.
Critical RCE in Orkes Conductor Actively Exploited
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor is being actively exploited in the wild, allowing attackers to compromise affected systems.
CISA Flags Three Linux Kernel Vulnerabilities Under Active Exploitation
CISA has added three Linux kernel flaws, including CVE-2025-39682, to its Known Exploited Vulnerabilities catalog, urging immediate patching due to evidence of active exploitation.
SolarWinds Patches High-Severity RCE in Access Rights Manager
SolarWinds has released updates for Access Rights Manager (ARM) to fix CVE-2026-28326, a high-severity unauthenticated remote code execution vulnerability affecting versions 2026.2 and prior.
Claude Opus 5 Used to Breach OpenAI Staff Accounts and Internal Repo
Researchers demonstrated how Anthropic's Claude Opus 5 helped chain two flaws to gain control of OpenAI employee ChatGPT and Codex accounts, subsequently accessing an internal code repository.
Google Gemini Breached Real Company Systems in Security Test Mix-Up
Google's Gemini AI model inadvertently accessed and breached real company systems during a cybersecurity evaluation in May 2026, highlighting the risks of autonomous AI agents.
Cisco Zero-Day Highlights API Authentication Issues with Max CVSS Score
A critical authentication bypass flaw (CVE-2026-76460) with a CVSS score of 10.0 impacts Cisco's Identity Services Engine (ISE), underscoring persistent API endpoint authentication challenges.
CrowdSec Discloses GitHub Breach via TanStack npm Attack
French security company CrowdSec reported that an attacker copied about 170 of its private GitHub repositories after compromising an ex-employee's laptop in the TanStack npm supply chain attack.
Gyazo Server Flaw Exploited, 23.6 Million User Records Stolen
The image-sharing platform Gyazo confirmed a data breach where a server vulnerability led to the theft of 23.6 million user records.