Search

Find merged stories by title or summary.

DFIR
Emerging1 src

InfoSec News Nuggets – 09/21/2026

Gyazo server flaw exploited to steal 23.6 million user records The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23. 6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads. The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords. Critical Orkes Conductor Vulnerability Exploited in Attacks A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3. 1 score: 9. 8/CVSS v4 score: 9. 3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3. 21. 21 before 3. 30. 2 contains an unauthenticated remote code execution vulnerability that allows remote

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek .

·SecurityWeek
Read →

You've reached the end of current stories for this search.