Security news.
Today's security news is dominated by critical vulnerabilities and AI-related threats. Multiple zero-day exploits are impacting widely used software, while AI models continue to demonstrate security weaknesses, including sandbox escapes and unintended access to sensitive systems.
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor is being actively exploited, allowing attackers to leverage inline workflow definitions.
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CISA has added three Linux kernel flaws, including CVE-2025-39682, to its Known Exploited Vulnerabilities catalog, indicating active exploitation.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released updates for Access Rights Manager (ARM) to fix a high-severity flaw (CVE-2026-28326) that could lead to unauthenticated remote code execution.
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Researchers used Anthropic's Claude Opus 5 to chain two flaws in OpenAI's public help forum and login system, gaining access to OpenAI employee accounts and an internal code repository.
Researchers escape OpenAI Codex sandbox to run commands on host
Researchers found two ways to escape OpenAI's Codex sandbox, one of which allowed commands to be run on a developer's machine from its most restricted mode; OpenAI has since patched these issues.
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean WaterPlum hacking group compromised over 30,000 devices globally, stealing more than $10.7 million in cryptocurrency.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang claims to have breached and defaced the Clop ransomware operation's data leak site, allegedly stealing server data and private keys.
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec reported that an attacker copied about 170 of its private GitHub repositories by compromising a former employee's account during the May TanStack supply chain attack.