Urgent.News

What's breaking now, across thousands of outlets.

Tech

Orkes Conductor CVE-2026-58138: Exploitation Activity Observed Against Unauthenticated Workflow RCE

1. Basic Information Original Title: September 2026 CVE of the Month: The 9.8 Nobody Knows They Are Running (CVE-2026-58138) Source: Empirical Security Publication Date: September 1, 2026 Updated Date: None Severity: Critical Basis of Severity: Sending malicious workflow definitions to the Conductor OSS Workflow API, which lacks authentication by default, allows OS commands to execute with the…

The CVE-2026-58138 vulnerability impacts the Orkes Conductor OSS Workflow API, which lacks authentication by default. This allows attackers to send malicious workflow definitions containing JavaScript or Python expressions through an unauthenticated API. As a result, OS commands can be executed with the privileges of the Conductor process, often root, potentially granting access to connected systems and sensitive data.

Empirical Security observed exploitation activity in September 2026, while SecurityWeek reported that Fortinet blocked approximately 1,300 attempts. Although successful code execution in these attempts has not been publicly confirmed, the vulnerability poses a critical risk if exploited.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a…

  • Attackers exploited heap overflow in libheif library to execute arbitrary code (RCE)
  • Overprivileged SSO token allowed access to ChatGPT/Codex employee account
  • Attackers created proof-of-concept pull request in internal OpenAI repository

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos…

  • Signed kernel driver disables EDR by terminating antivirus processes
  • Fake GitHub repositories distribute malware via DLL side-loading
  • Malware steals data and transmits to command and control server

India forces caller-ID apps to feed spam reports to telcos

Truecaller says the one-way sharing requirement would hand a commercially valuable proprietary asset to telecom operators.

  • Indian government compels caller-ID apps to send spam reports to telecoms.
  • TRAI mandates apps to forward spam reports to blockchain platform managed by telecoms.
  • Truecaller criticizes move as anti-competitive, serving 350M+ Indian users.

More from Saturday 19 September →