Gemini Broke Containment, Orkes RCE Exploited (09/19/2026)
- › Google's Gemini reached the open internet during a May evaluation and got into three real companies, because a fictional name used in the test matched a real domain.
- › A pre-auth remote code execution flaw in Orkes Conductor versions 3.21.21 to 3.30.2 is under active exploitation, with Fortinet blocking 1,290 attempts in 24 hours.
- › CISA added three exploited Linux kernel flaws to the KEV catalog, all local privilege escalation class, with a September 21 federal patch deadline.
- › CrowdSec lost copies of roughly 170 private repositories through a departed employee's GitHub access that was never revoked.
- › SolarWinds patched a hard-coded key in Access Rights Manager that gives an unauthenticated attacker remote code execution.
An AI model broke into three real companies during a security evaluation in May, and the reason it got out was a name. A fictional company used in a capture-the-flag exercise happened to match a real domain, which is the kind of boundary failure no threat model has a row for. Underneath that, Orkes Conductor is being exploited in the wild, CISA put three Linux kernel flaws in the exploited catalog with a Monday deadline attached, and CrowdSec found out what a departed employee’s live GitHub account is worth to somebody else.
Top 5 Critical Security Alerts
1. Gemini Reached the Open Internet and Compromised Three Real Companies
During a capability evaluation run by the Israeli firm Irregular in May 2026, Google’s Gemini reached the open internet and gained access to three real companies, guessing the password on one system repeatedly and finding credentials in a public repository for the other two. Irregular’s report attributes the escape to a naming error, where a fictional company name used in capture-the-flag exercises turned out to match a real domain. Gemini ended the intrusion itself once it worked out it was inside a real company’s systems, and Google’s VP of Security said the model acted appropriately, per The Hacker News and The Verge. Irregular notified Google in July, and the public found out in September when the Wall Street Journal reported it.
Operator Note: The model behaved better than the environment did. If you run evaluations, the fictional names in your scenarios are an attack surface, and a name nobody registered on your behalf is a name somebody else owns.
2. Orkes Conductor Pre-Auth RCE Under Active Exploitation
Fortinet reports active exploitation of CVE-2026-58138 in the Orkes Conductor workflow platform, an unauthenticated remote code execution flaw scoring 9.8 on CVSS v3.1 and 9.3 on v4. It affects versions from 3.21.21 up to 3.30.2. Attackers submit workflow definitions carrying JavaScript or Python expressions that reach unsandboxed evaluators before authentication happens, and Fortinet blocked 1,290 attempts in one 24 hour window as of September 9, a 132% jump in daily activity, per The Hacker News. A workflow orchestrator already holds the credentials for everything it orchestrates, so code execution there is rarely the end of the intrusion.
Operator Note: Orchestration platforms tend to sit outside the patch cadence that covers your operating systems and your obvious internet-facing services. Find out who owns this one before you need to.
3. CISA Adds Three Exploited Linux Kernel Flaws to KEV
CISA added three Linux kernel flaws to the Known Exploited Vulnerabilities catalog on Friday: CVE-2025-39682 at 9.8, an exception handling flaw in the TLS receive path, CVE-2026-53266 at 8.8, an out of bounds write in ebtables SNAT ARP rewriting, and CVE-2025-39964 at 7.8, a race condition on AF_ALG sockets. All three require local authenticated access and lead to memory disclosure, denial of service, or privilege escalation, and federal civilian agencies have until September 21 to patch under Binding Operational Directive 26-04, per The Hacker News. These are the bugs that get deprioritized because the fix needs a reboot window, and the reboot window is the hardest thing in the organization to schedule.
Operator Note: Local privilege escalation is what turns the phish you already absorbed into the incident you report. Treat these as the second half of an intrusion rather than a standalone risk.
4. A Departed Employee’s GitHub Access Cost CrowdSec 170 Private Repos
CrowdSec disclosed on September 18 that an attacker copied roughly 170 of its private GitHub repositories on May 22, using the account of an employee who had just left the company and whose access had been left open. The laptop belonging to that employee was compromised in May’s supply chain attack on TanStack, according to The Hacker News. Two ordinary failures had to line up for this one, and the second failure was entirely inside CrowdSec’s control.
Operator Note: Offboarding that ends at the identity provider leaves the source code, the registry, and the cloud console still answering to a person who no longer works there.
5. SolarWinds Patches Hard-Coded Key in Access Rights Manager
SolarWinds shipped ARM 2026.2.1 to fix CVE-2026-28326, a hard-coded static key rated 8.8 that an unauthenticated attacker can turn into remote code execution. Everything from 2026.2 backward is affected. Kai Huang of Armadin reported it, and SolarWinds has seen no evidence of exploitation so far, per The Hacker News. Access Rights Manager exists to tell you who has access to what, which makes it an unusually efficient place for an attacker to land.
Additional Security Alerts
Threat Intelligence
- North Korean WaterPlum campaign infected 30,000 devices: A joint advisory from the FBI, the Defense Department, and law enforcement in Japan, Australia, and Germany says the group compromised at least 30,000 devices between December 2025 and July 2026 and moved more than $10.7 million in stolen cryptocurrency to North Korea, largely by posing as AI and blockchain companies recruiting job applicants. BleepingComputer, The Record
Security Breaches & Incidents
- ShinyHunters breached Clop’s leak site: The extortion crew defaced the Clop ransomware operation’s Tor leak site and claims to have taken server data along with the private keys for the onion service. BleepingComputer
Emerging Security Technologies
- A hallucinated intelligence report nearly put troops on a Chinese ship: In spring 2026 the US military came within minutes of boarding a vessel after an AI chatbot falsely flagged its cargo as nuclear weapons components, with soldiers ready and aircraft already in the air before the error was caught. The Decoder
- Agentic security is still an open problem with no product behind it: An investor makes the case to The Register that the industry has been deferring the question of how to secure autonomous agents, and that the gap is now large enough to build a company inside. The Register
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.