Sam's News — security — 2026-09-19¶
Cybercrime¶
8.5 North Korean WaterPlum Hackers Compromised 30,000 Devices Worldwide; Stole $10.7M in Crypto¶
North Korean hacking group WaterPlum compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, stealing $10.7 million in cryptocurrency through a fake job recruitment scheme targeting tech developers. Seven international agencies jointly attributed the operation to North Korea's state apparatus.
- 30,000+ devices compromised across 100+ countries
- $10.7 million in cryptocurrency stolen
- 7,000 crypto accounts drained of credentials
- Attack vector: fake recruitment for crypto, NFT, and AI firms
- Attributed to North Korea's 313 General Bureau; joint advisory from FBI, Japan, Australia, Germany
Sources: AMBCrypto AI Web Searched, Cryptopolitan AI Web Searched, BleepingComputer RSS
Security¶
8 CISA Flags Three Linux Kernel Vulnerabilities Under Active Exploitation¶
CISA added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 19, 2026. CVE-2025-39682 (CVSS 9.8) allows local users to trigger memory disclosure or denial-of-service; CVE-2026-53266 (CVSS 8.8) enables privilege escalation; CVE-2025-39964 (CVSS 7.8) is a race condition in cryptographic operations.
- CVE-2025-39682: CVSS 9.8, local authenticated users trigger memory disclosure/DoS
- CVE-2026-53266: CVSS 8.8, out-of-bounds write enables privilege escalation
- CVE-2025-39964: CVSS 7.8, race condition crashes system or corrupts crypto results
- Red Hat issued advisories confirming active exploitation on September 19
- Federal agencies recommended to apply fixes by September 21, 2026
Sources: The Hacker News AI Web Searched
8 Claude Opus 5 Used to Breach OpenAI Employee Accounts¶
Security researchers at Hacktron used Anthropic's Claude Opus 5 to exploit chained vulnerabilities and take over multiple OpenAI employee accounts and access internal repositories.
- Used Claude (Opus 4.8 and 5) to build working exploit for libheif vulnerability
- Libheif bug fixed upstream a year earlier but never assigned CVE or security flag
- Sign-in tokens for community forum carried excessive permissions to ChatGPT, Codex, GitHub, Slack, email
- Researchers demonstrated account takeover by accessing OpenAI's GitHub organization
- Three-person Hacktron AI team exploited an ImageMagick/libheif vulnerability via HEIC image uploads
- Sign-in tokens for OpenAI's community forum carried excessive permissions to ChatGPT and Codex accounts
- Libheif bug had been fixed upstream but never formally assigned a CVE number
- OpenAI awarded $6,500 bug bounty; vulnerabilities resolved
Sources: The Hacker News RSS Update to: Hacktron Demonstrates Account Takeover Flaw in OpenAI Via AI-Generated Exploit
7.5 Critical Unauthenticated RCE Vulnerability in Orkes Conductor Actively Exploited¶
A critical remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor workflow platform is being actively exploited in the wild.
- CVSS score 9.8 (critical)
- Patched in June 2026 (version 3.30.2)
- Proof-of-concept published early August; in-the-wild exploitation confirmed August 21
- Fortinet blocked ~1,300 exploitation attempts September 8–9
- GraalVM HostAccess.ALL configuration disables sandboxing
Sources: The Hacker News RSS Update to: Critical Orkes Conductor Remote Code Execution Vulnerability Exploited
7.5 McKesson Confirms Data Breach as Attacker Deadline Approaches¶
Healthcare distributor McKesson Corporation confirmed a cybersecurity incident discovered August 25, 2026, involving unauthorized data theft affecting customers in its Oncology & Multispecialty and Medical-Surgical units. ShinyHunters claimed responsibility, alleging theft of 284 million records and demanding $55 million ransom with a September 1 deadline.
- Incident discovered August 25, 2026; confirmed August 31
- ShinyHunters claimed 284 million records stolen
- $55 million ransom demanded with September 1 deadline
- Affected Oncology & Multispecialty and Medical-Surgical units
- McKesson delivers approximately one-third of North American prescription medicines
- Offering complimentary credit monitoring and identity protection to impacted individuals
Sources: SecurityWeek AI Web Searched
7.5 SolarWinds Patches Critical Hard-Coded Key Vulnerability in ARM¶
SolarWinds released security patches on September 17, 2026, for CVE-2026-28326, a high-severity hard-coded key vulnerability in Access Rights Manager enabling unauthenticated remote code execution. The flaw, rated 8.8 on the CVSS scale, affects all versions through 2026.2 and was patched in version 2026.2.1. No evidence of exploitation in the wild has been reported.
- CVE-2026-28326: hard-coded key vulnerability in Access Rights Manager
- CVSS severity rating 8.8, enables unauthenticated remote code execution
- Affects ARM versions 2026.2 and prior; patched in 2026.2.1
- No evidence of exploitation in the wild
Sources: The Hacker News AI Web Searched
7.5 BragJack Attack Hijacks AI Browser Agents via Malicious Extensions¶
A proof-of-concept attack called BragJack uses a malicious browser extension to hijack AI assistants in Chrome, Edge, and other browsers, earning over $20,000 in security bounties.
- CVE-2026-0628 (Chrome, CISA 8.8/10) fixed in version 143.0.7499.192 in January 2026
- CVE-2026-55945 (Edge, severity 4.2) fixed in version 150.0.4078.48 on July 2, 2026
- Comet, Opera Neon, and Claude vulnerabilities have no CVE assigned
- Researcher earned approximately $20,000 total in bug bounties across five products
Sources: BleepingComputer RSS Update to: Browser extension vulnerability could hijack AI assistants across Chrome, Edge, Opera, and Claude
7 TanStack Supply Chain Attack Led CrowdSec Attacker to Copy 170 Private Repositories¶
An attacker exploited a departed employee's GitHub access—left open after May's TanStack supply chain attack—to copy approximately 170 of CrowdSec's private repositories on May 22. The repositories contained CrowdSec's web console, data science models, and consensus algorithm for IP blocklist determination; the leaked code surfaced September 16.
- May 11, 2026: 84 malicious TanStack npm packages deployed (CVE-2026-45321)
- Stolen credentials: GitHub tokens, SSH keys, cloud credentials from developer machines
- May 22: Attacker copied ~170 CrowdSec private repositories using stolen token
- CrowdSec removed account May 25 (three days after copy)
- Leaked code surfaced September 16; disclosed September 18
- Leaked 83 CrowdSec user emails and 51 potential investor names/emails from 2020
- Code was approximately four months old at breach time
- Also affected Mistral AI and OpenAI
Sources: The Hacker News AI Web Searched
6.5 TigerByte Cyber Launches with $3 Million Seed Funding and $7M in Government Contracts¶
Cybersecurity startup TigerByte Cyber emerged from stealth with $3 million in funding and over $7 million in contracts from US government agencies including the Space Force and Navy.
Sources: SecurityWeek RSS
6 ShinyHunters extortion gang breaches Clop ransomware leak site¶
The ShinyHunters extortion group hacked the Clop ransomware operation's data leak site, defaced it, and allegedly stole server data and cryptographic keys.
Sources: BleepingComputer RSS