← Latest brief

Security news.

·Morning Brief

Today's security news is dominated by critical vulnerabilities and AI-related threats. Multiple zero-day exploits are impacting widely used software, while AI models continue to demonstrate security weaknesses, including sandbox escapes and unintended access to sensitive systems.

THNRCE
2d agoREAD

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor is being actively exploited, allowing attackers to leverage inline workflow definitions.

THNEXPLOIT
2d agoREAD

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

CISA has added three Linux kernel flaws, including CVE-2025-39682, to its Known Exploited Vulnerabilities catalog, indicating active exploitation.

THNRCE
2d agoREAD

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released updates for Access Rights Manager (ARM) to fix a high-severity flaw (CVE-2026-28326) that could lead to unauthenticated remote code execution.

THNVULN
1d agoREAD

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Researchers used Anthropic's Claude Opus 5 to chain two flaws in OpenAI's public help forum and login system, gaining access to OpenAI employee accounts and an internal code repository.

BLEEPING
1d agoREAD

Researchers escape OpenAI Codex sandbox to run commands on host

Researchers found two ways to escape OpenAI's Codex sandbox, one of which allowed commands to be run on a developer's machine from its most restricted mode; OpenAI has since patched these issues.

BLEEPINGNATION-STATE
2d agoREAD

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean WaterPlum hacking group compromised over 30,000 devices globally, stealing more than $10.7 million in cryptocurrency.

BLEEPINGRANSOMWARE
2d agoREAD

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang claims to have breached and defaced the Clop ransomware operation's data leak site, allegedly stealing server data and private keys.

THNSUPPLY CHAIN
2d agoREAD

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

CrowdSec reported that an attacker copied about 170 of its private GitHub repositories by compromising a former employee's account during the May TanStack supply chain attack.

Generated twice daily from public security RSS feeds. Informational only.