Weekly review

ThreatNoir Weekend Brief — September 19

2026-09-19Afternoon6 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 19, 2026

The cybersecurity landscape continues to deteriorate as critical vulnerabilities across multiple platforms face active exploitation, while artificial intelligence accelerates the discovery of new security flaws at an unprecedented rate. Today's threat intelligence reveals urgent patching requirements for enterprise infrastructure, supply chain compromises affecting major security vendors, and emerging privacy concerns surrounding AI-powered services.

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability in Orkes Conductor is currently being exploited by threat actors in active campaigns. The flaw, designated CVE-2026-58138 with a CVSS v3.1 score of 9.8 and CVSS v4 score of 9.3, enables unauthenticated remote code execution against affected systems. Versions of Orkes Conductor prior to 3.30.2 remain vulnerable to this pre-authentication attack vector. Source: The Hacker News

Organizations deploying Orkes Conductor should prioritize immediate patching to version 3.30.2 or later to mitigate the risk of compromise. The active exploitation of this vulnerability underscores the need for rapid vulnerability assessment and remediation protocols within workflow orchestration environments.

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The three flaws include CVE-2025-39682 with a CVSS score of 9.8, along with CVE-2025-39964 and CVE-2026-53266. The vulnerabilities span multiple attack vectors, including improper exception handling in the TLS receive path and other critical kernel functions. Source: The Hacker News

The inclusion of these vulnerabilities in CISA's KEV catalog signals that remediation is now a priority for federal agencies and critical infrastructure operators. Linux system administrators must evaluate their kernel versions and apply available patches to prevent exploitation by threat actors actively targeting these flaws.

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

While AI development labs discuss industry-wide agreements to slow technological advancement, the opposite phenomenon is occurring in the security domain. Widely available AI chatbots are accelerating the discovery and documentation of security vulnerabilities at a scale that threatens to overwhelm traditional security response capabilities. Source: Wired

The paradox of AI-assisted vulnerability discovery presents both opportunities and challenges for security teams. As artificial intelligence tools lower the barrier to entry for identifying flaws, organizations face mounting pressure to develop more efficient patch management and vulnerability prioritization strategies to keep pace with the accelerating disclosure rate.

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released security updates addressing a high-severity vulnerability in its Access Rights Manager product that enables unauthenticated remote code execution. CVE-2026-28326, rated 8.8 on the CVSS scale, stems from a hard-coded cryptographic key present in the application. All versions of Access Rights Manager 2026.2 and prior are affected by this flaw. Additional related vulnerabilities tracked as CVE-2026-28299, CVE-2026-28302, CVE-2026-28304, CVE-2026-28317, CVE-2026-28321, and CVE-2026-28323 have also been addressed in the patch release. Source: The Hacker News

The presence of hard-coded credentials in identity and access management software represents a critical risk to enterprise security posture. Organizations relying on SolarWinds ARM should apply available patches immediately to prevent unauthorized administrative access to their identity management infrastructure.

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

CrowdSec disclosed that approximately 170 of its private GitHub repositories were copied by an attacker following a supply chain compromise affecting TanStack npm packages. The incident occurred on May 22 when a former employee's GitHub account, which remained active despite their departure, was compromised through a laptop infected during the TanStack supply chain attack. The attacker leveraged the compromised account to exfiltrate sensitive source code and credentials. Source: The Hacker News

This incident demonstrates the cascading nature of supply chain attacks and the critical importance of promptly revoking access for departing employees. The compromise of CrowdSec's repositories through the TanStack attack vector illustrates how a single vulnerability in a widely-used dependency can create secondary compromise opportunities across the security vendor ecosystem.

Calling Viral AI Actress Tilly Norwood? Agree to a Face Scan First

A viral AI service featuring digital actress Tilly Norwood offers video call interactions requiring face scanning for age verification. The "Talking Tilly" service collects facial biometric data and mood analysis information from all callers under a privacy framework citing "legitimate interests" as the legal basis for processing. The service is scheduled to shut down permanently on September 27. Source: Bleeping Computer

The emergence of AI-powered services collecting biometric and behavioral data raises significant privacy and consent concerns. Users engaging with such services should carefully review the terms of service and understand the scope of personal data collection, particularly regarding facial recognition and emotional analysis capabilities that may extend beyond stated age verification purposes.

The convergence of active exploitation campaigns, accelerating vulnerability discovery, and emerging privacy risks demands heightened vigilance from security teams and infrastructure operators across all sectors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).