Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

2026-09-19T13:23:59Z•b3fd744f02074c190bd0863ac8d5bd114c7b7e1d6940a8537f97718ca4dcc8d5
CVE-2025-39682CVE-2026-28326CVE-2026-58138CVE-2026-77179CVE-2026-81642CVE-2026-85889AI-securityAPTAzure-AI-FoundryCISA-KEVDocker-SandboxesFamousSparrowHandala-HackLinux-kernelOrkes-ConductorSolarWinds-ARMTransparent-TribeUnbound-DNSWordPressactive-exploitationinformation-stealernpm-malwareprivilege-escalationremote-code-executionsupply-chain-attackunauthenticated-rcevulnerability

What happened

The document is a security-news feed covering multiple high-impact vulnerabilities, active exploitation, malware campaigns, supply-chain compromises, AI-agent risks, and state-linked threat activity. Notable items include actively exploited unauthenticated RCE in Orkes Conductor (CVE-2026-58138), critical flaws in Docker Sandboxes and Unbound DNSSEC, a CVSS 10 Azure AI Foundry privilege-escalation flaw, SolarWinds ARM RCE, Linux kernel vulnerabilities added to CISA KEV, npm-based information stealers, repository theft following a supply-chain compromise, and backdoors attributed to Iran- and‍/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b3fd744f02074c190bd0863ac8d5bd114c7b7e1d6940a8537f97718ca4dcc8d5
Enrichment time
2026-09-19T13:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.