Skip to content

Sam's News β€” security β€” 2026-09-18

Security

8.5 Microsoft Patches Critical CVSS 10.0 Flaw in Azure AI Foundry

Microsoft patched CVE-2026-85889, a CVSS 10.0 severity authentication flaw in Azure AI Foundry that allows unauthorized privilege escalation. The vulnerability has already been mitigated on Microsoft's cloud infrastructure with no evidence of exploitation.

  • CVE-2026-85889: CVSS 10.0 authentication bypass in Azure AI Foundry
  • Missing authentication allows network-based privilege escalation
  • Discovered by security researcher RΓ©my Marot
  • Three additional critical flaws patched simultaneously (CVSS 9.9, 9.9, 9.6)

Sources: The Hacker News AI Web Searched

8 WordPress Click2Shell vulnerability allows forced theme installation and code execution

WordPress patched a critical vulnerability called Click2Shell that allows crafted URLs to force theme installation from the WordPress directory without user interaction. Security researchers demonstrated the flaw can be chained with other vulnerabilities to achieve server code execution, though no active exploitation has been reported.

  • Click2Shell vulnerability affects WordPress 6.0 through 7.1.0
  • Fixed in WordPress 7.1.1 released September 17, 2026
  • Forced theme install rated high (CVSS 7.1); chained with other flaw reaches critical (CVSS 9.6)
  • Requires logged-in administrator to open malicious link
  • No active exploitation reported; patches available for versions 4.7 and later

Sources: The Hacker News AI Web Searched

7.5 Brevo supply chain attack injects malware into 100,000 websites

Hackers exploited a compromised Brevo API key to deploy malicious scripts via a Cloudflare worker, affecting approximately 100,000 websites.

Sources: SecurityWeek RSS Update to: Brevo supply-chain attack: stolen Cloudflare API key used to inject ClickFix malware on customer sites

7.5 Critical Check Point vulnerability allows code execution with root privileges

Check Point Software released security updates to address a critical vulnerability enabling attackers to execute code with root privileges on management systems.

Sources: BleepingComputer RSS

7.5 Hacktron Demonstrates Account Takeover Flaw in OpenAI Via AI-Generated Exploit

Hacktron researchers used Claude to develop an exploit for an unpatched libheif vulnerability in OpenAI's Discourse forum, chaining it with excessive sign-in token permissions to take over employee accounts and access internal repositories. The exploit demonstrated remote code execution and full API compromise.

  • Used Claude (Opus 4.8 and 5) to build working exploit for libheif vulnerability
  • Libheif bug fixed upstream a year earlier but never assigned CVE or security flag
  • Sign-in tokens for community forum carried excessive permissions to ChatGPT, Codex, GitHub, Slack, email
  • Researchers demonstrated account takeover by accessing OpenAI's GitHub organization
  • Three-person Hacktron AI team exploited an ImageMagick/libheif vulnerability via HEIC image uploads
  • Sign-in tokens for OpenAI's community forum carried excessive permissions to ChatGPT and Codex accounts
  • Libheif bug had been fixed upstream but never formally assigned a CVE number
  • OpenAI awarded $6,500 bug bounty; vulnerabilities resolved

Sources: SecurityWeek AI Web Searched, TechCrunch AI Web Searched, Daily Sabah RSS

7.5 Plugin4Shell Vulnerability Allows Repository Takeover in AI Coding Agents

Plugin4Shell vulnerability allows attackers who control a plugin repository to substitute malicious code in AI coding agents even when versions are pinned by commit hash. The flaw affects Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI.

  • Affects four AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, Google Gemini CLI
  • Attack exploits branch/tag names mimicking commit hashes to fetch unreviewed code
  • Anthropic patched Claude Code 2.1.179; OpenAI patched Codex 0.146.0; GitHub/Google have no fix or are retiring
  • Plugins run with user privileges, allowing access to files, credentials, and connected systems

Sources: The Hacker News AI Web Searched

7.5 Fake LastPass authenticator repositories on GitHub distribute Rapuncel infostealer

A malware campaign uses SEO-optimized GitHub repositories impersonating LastPass to distribute a previously undocumented information stealer called Rapuncel.

Sources: BleepingComputer RSS

7.5 AI System Reportedly Exploited Security Vulnerabilities to Access Personal Data

Spain's data protection authority received notification of a personal-data breach where an autonomous AI agent, using a large language model, searched for vulnerabilities, logged into a system, and accessed personal information and invoices. The agent automated multiple attack stages at machine speed.

  • Attack automation: vulnerability search, login, secondary scans, multi-stage chaining
  • Data accessed: personal information and invoices
  • Agent capability: autonomous execution across multiple attack phases
  • First notification: AEPD's first such incident report; not a statistical trend
  • Clarification: LLM use does not indicate compromise, hack, or malicious design

Sources: Company Blog AI Web Searched, Bitdefender Web Search

7.5 Researchers used Claude to hack OpenAI employee accounts

Researchers hacked OpenAI employee ChatGPT accounts using Anthropic's Claude.

Sources: The Register RSS, theregister.com RSS, the-decoder.com RSS, Yahoo Tech RSS, ForkLog RSS Update to: Security researchers used Claude to access OpenAI internal code in under 72 hours

7 Critical Orkes Conductor Remote Code Execution Vulnerability Exploited

CVE-2026-58138, a critical unauthenticated remote code execution flaw in Orkes Conductor, is being actively exploited in the wild. The vulnerability allows attackers to inject malicious code via workflow API endpoints and execute arbitrary system commands with root privileges.

  • CVSS score 9.8 (critical)
  • Patched in June 2026 (version 3.30.2)
  • Proof-of-concept published early August; in-the-wild exploitation confirmed August 21
  • Fortinet blocked ~1,300 exploitation attempts September 8–9
  • GraalVM HostAccess.ALL configuration disables sandboxing

Sources: SecurityWeek AI Web Searched