The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
Orkes Conductor Pre-Auth RCE Is Live in the Wild
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Monday, September 21, 2026. Fortinet has an outbreak alert on a perfect-nine-point-eight unauthenticated remote code execution bug in Orkes Conductor, C.V.E. twenty twenty-six dash fifty-eight thousand one hundred thirty-eight, and attackers are already throwing it. Submit a hostile workflow definition with JavaScript or Python to the workflow A.P.I. before login, abuse GraalVM evaluators left on HostAccess.ALL, and you get arbitrary O.S. commands as the Conductor process. No credentials required. Public proof-of-concept code is out, including a working exploit for three point twenty-three, and FortiGuard blocked roughly thirteen hundred attempts in a single day plus nearly sixty-seven hundred over a week. Conductor orchestrates microservices, workflows, and A.I. agents, so an exposed instance is not a niche hobby box. The fix landed in three point thirty point two back in June, but opportunists are still scanning. Pull anything before three point thirty point two, yank the workflow A.P.I. off the open internet, and hunt for weird child processes under the Conductor service. An orchestration plane that runs unauthenticated scripts is just a free shell with better branding. SentinelOne tied North Korea's Jade Sleet, also tracked as TraderTraitor, to a breach at an India-based I.T. services provider through one Apple Silicon MacBook owned by a DevOps engineer. The kit matches the FLATROOF and ROOFDECK Rust macOS backdoors previously seen in the KelpDAO LayerZero heist, with FLATROOF talking Telegram and ROOFDECK riding the Nostr protocol for decentralized C-two. A malicious Cursor workspace showed up in the trail, and the laptop held Terraform, Ansible, and cloud credentials for A.W.S., O.V.H., and OpenStack. Same playbook, different industry: fake coding interviews and weaponized repos aimed at developers whose laptops can reach production. The value of the target is whatever that Mac can touch, crypto or not. If your DevOps folks live in Cursor and keep cloud keys on the endpoint, treat interview homework and random Terraform clones like untrusted binaries, because Jade Sleet already does. Three researchers at Hacktron used Anthropic's Claude Opus 5 to chain two flaws, take over ChatGPT and Codex accounts belonging to OpenAI employees, and reach an internal OpenAI code repo, all in under seventy-two hours as authorized research. The path started with a libheif image bug in the Discourse forum software, flipped into remote code execution with the model's help after Opus four point eight failed, then walked through an OpenAI single-sign-on weakness so forum compromise became staff account takeover with no victim click. They proved impact by prompting a compromised employee's connected Codex to open a harmless pull request in the private monorepo, then stopped. OpenAI fixed its side in about fourteen hours and paid a sixty-five hundred dollar bounty. The forum was out of bounty scope
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472
Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764