Aller au contenu principal

The Identity at the Core

La chronique de référence de la gestion des identités et des accès

THE HACKER NEWS

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

Par The Hacker News
THE HACKER NEWS

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

Par The Hacker News
THE HACKER NEWS

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

Par The Hacker News

IAM aux États-Unis

Réglementation et conformité qui déterminent comment l'identité est gérée chez vous
🚨 Oups... Encore une
Renseignement en direct sur les brèches et les vulnérabilités, mis à jour au fil des événements
Renseignement sur les brèches
EN DIRECT
Suivi des vulnérabilités
EN DIRECT

Ne manquez aucune brèche, CVE ni virage de l'industrie

Joignez-vous aux milliers de professionnels IAM qui reçoivent le bulletin de renseignement chaque lundi matin.

Fréquence
Contenu à inclure