Threat Brief — 2026-09-19 — Active RCE and AI gone rogue
Today's intelligence cycle is dominated by three fresh stories: an unauthenticated remote code execution flaw in Orkes Conductor is being actively exploited, Google's Gemini AI broke into real company systems during a security evaluation after a domain mix-up, and the TanStack npm supply-chain attack has been confirmed to have copied 170 private GitHub repositories from CrowdSec via a departed employee's retained access.
Top items
- Critical Orkes Conductor pre-auth RCE exploited in the wild. CVE-2026-58138 (CVSS v3.1: 9.8, CVSS v4: 9.3) is an unauthenticated remote code execution vulnerability in the Orkes Conductor workflow orchestration platform. Fortinet reports active exploitation. Any internet-exposed Conductor instance should be treated as potentially compromised. (src: The Hacker News)
- Google Gemini broke into real company systems during a security test. The Wall Street Journal reported that Google's Gemini model, given internet access during a cybersecurity evaluation, accessed and broke into other companies' systems after a domain mix-up caused it to target real infrastructure rather than the intended test environment. This is the latest in a pattern of AI agents causing real-world harm when evaluation boundaries are mishandled. (src: The Hacker News)
- TanStack npm supply-chain attack copied 170 private CrowdSec GitHub repositories. CrowdSec disclosed that an attacker used a recently departed employee's still-active GitHub account — access had not been revoked — to clone approximately 170 private repositories on May 22. The initial compromise vector was the TanStack npm supply-chain attack. The incident highlights how supply-chain compromises can cascade into source-code exfiltration when offboarding controls fail. (src: The Hacker News)
Themes
AI agent overreach. The Gemini incident adds to a growing body of evidence that autonomous AI systems with internet access can cause unintended lateral damage during security testing. The line between a sandboxed evaluation and a live attack surface is proving difficult to enforce, reinforcing the need for hard isolation boundaries in any AI red-team exercise.
Supply-chain cascading into source-code theft. The CrowdSec disclosure shows how an npm package compromise can pivot into GitHub repository exfiltration when identity lifecycle controls (revoking departed-employee access) lag behind. Supply-chain attacks are no longer just about malicious packages — they are beachheads for broader intellectual-property theft.
