Security news.
Today's cybersecurity news is heavily influenced by AI, with new research revealing AI models assisting in vulnerability discovery, sandbox escapes, and even account takeovers. Additionally, critical vulnerabilities, including actively exploited zero-days and CISA KEV additions, demand immediate attention, alongside ongoing supply chain attacks and widespread data breaches.
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts
Researchers chained two flaws, starting with a bug in OpenAI's public help forum, to compromise employee ChatGPT and Codex accounts and access an internal code repository.
Researchers Escape OpenAI Codex Sandbox
Security researchers successfully escaped OpenAI's Codex sandbox in two different ways, demonstrating the ability to run commands on the host machine from its most restricted mode. OpenAI has since patched both vulnerabilities.
Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138, CVSS 9.8) in Orkes Conductor is being actively exploited, allowing attackers to exploit it via inline workflow definitions.
CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog
CISA has flagged three Linux kernel flaws (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266) to its Known Exploited Vulnerabilities catalog, urging immediate patching due to active exploitation that can lead to local root privileges.
Malicious npm Packages Evade Install-Script Defenses
An ongoing npm malware campaign, notably involving the 'indexed-btree' package, is bypassing supply chain defenses by embedding malicious code in a package's normal runtime behavior instead of detection-prone installation scripts.
Gyazo Server Flaw Exploited, 23.6 Million User Records Stolen
The image-sharing platform Gyazo confirmed a data breach where hackers exploited a server vulnerability to steal 23.6 million user records.
North Korean WaterPlum Hackers Infected 30,000 Devices
A joint advisory warns that the North Korean WaterPlum hacking group compromised at least 30,000 devices globally between December 2025 and July 2026, siphoning over $10.7 million in cryptocurrency.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds released updates for a high-severity flaw (CVE-2026-28326, CVSS 8.8) in Access Rights Manager (ARM) that could lead to unauthenticated remote code execution in all versions 2026.2 and prior.