September 21, 2026
Command View
Verification cutoff (exact UTC)
September 21, 2026, 13:12:10 UTC.
Priority posture (RED/AMBER/WATCH/CONTEXT)
RED is warranted for three immediate control-plane conditions: reported manipulation of operational technology at two Colorado water utilities; active exploitation of unauthenticated remote code execution in Orkes Conductor; and the CISA-listed Linux kernel vulnerabilities whose federal remediation date is September 21. These are separate events. The Colorado incident has not been attributed to the Iranian-linked water campaign, and the Linux reporting does not establish a single exploit chain.
AMBER covers the confirmed May source-code exposure at CrowdSec through the TanStack compromise path, and the still-active software-supply-chain targeting of Rust maintainers and crate owners. WATCH covers unconfirmed actor linkage, incomplete victim scope, and any downstream use of exposed code or stolen developer credentials.
Today’s decisions
- Water and wastewater operators should treat any unexplained PLC, alarm, remote-access, or pumping-cycle change as a possible integrity incident: move remote access behind a controlled gateway, verify process state locally, compare controller configurations with known-good images, preserve logs, and coordinate operational and safety decisions with the plant owner.
- Orkes Conductor owners should identify every deployment between 3.21.21 and 3.30.1, upgrade to 3.30.2 or later, restrict the workflow API, and investigate unauthorized workflow definitions, child processes, outbound connections, and secrets access. A patch alone does not close an already exploited instance.
- Linux owners should patch and reboot affected systems using the distribution’s fixed kernel, then examine privileged services and local-user activity. The three CVEs have different prerequisites and impacts; do not treat “local attacker” as low impact after a foothold exists.
- Software and security-tooling owners should inventory TanStack dependencies and CrowdSec integrations, rotate tokens that could have been present during the May exposure window, and require provenance checks for developer packages, CI/CD actions, and release artifacts.
- Teams with unresolved exposure from previously briefed Cisco, GitLab, Acronis, Siemens, maritime, or other high-consequence cases should keep those investigations open until compromise assessment—not merely patch installation—is complete.
Threat and Resilience Ledger
[RED] — Water and wastewater OT | Colorado, North America — Reported attackers changed control settings at two small utilities
SecurityWeek reported September 21 that two private Colorado water utilities, each serving fewer than 200 people, were targeted in late August. A spokesperson for Governor Jared Polis told The Denver Post that attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. The disruptions were brief and did not affect water service or public safety. The utilities and the initial-access path have not been named. The spokesperson described the actors only as foreign and referenced ongoing Iranian-backed efforts against drinking-water and wastewater systems; no link to the July multi-state campaign has been established. Operators should verify controller logic, alarm state, remote-access configuration, engineering accounts, and physical process conditions before restoring normal connectivity. Fixed version: not applicable; this is an incident response matter. Evidence: incident details reported by SecurityWeek from a Colorado governor’s-office spokesperson and a paywalled Denver Post report. Attribution: unknown; Iranian linkage unconfirmed. Confidence: moderate for the reported control changes and lack of service impact; low for actor identity or campaign linkage. Uncertainty: utility names, affected vendors/models, persistence, and whether any data or credentials were taken. Sources: SecurityWeek, “Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems,” September 21, 2026; Colorado governor’s-office statement as relayed by SecurityWeek.
[RED] — Workflow orchestration and AI automation | Global — Orkes Conductor CVE-2026-58138 is being actively exploited
Fortinet’s FortiGuard service and SecurityWeek report active attacks against Orkes Conductor, an orchestration framework used for microservices, workflows, and AI-agent activity. CVE-2026-58138 is an unauthenticated remote-code-execution flaw in the workflow API: a malicious inline workflow definition can supply JavaScript or Python expressions that reach arbitrary operating-system command execution. Reported affected releases are 3.21.21 through 3.30.1; the fixed release is 3.30.2. Treat Conductor as a privileged control plane: restrict exposure, place the API behind authentication and network controls, inspect workflow definitions and process creation, and rotate secrets if exploitation is suspected. Evidence: Fortinet reports active targeting; independent research and public exploit material corroborate the version range and fixed release. Attribution: unknown. Confidence: high for the vulnerability, affected range, fixed release, and active-exploitation report; victim count is unknown. Uncertainty: attacker access to downstream services, tenant separation, and the number of successfully compromised servers. Sources: Fortinet FortiGuard, SecurityWeek, CVE/NVD, and OpenTaint.
[RED] — Linux kernel and server control plane | Global — Three CISA-listed kernel flaws require immediate closure
CISA’s September 18 dated alert added CVE-2025-39964 and CVE-2026-53266 to the Known Exploited Vulnerabilities action set; current reporting identifies CVE-2025-39682 as part of the same three-flaw Linux kernel warning. The defects are distinct: CVE-2025-39682 concerns a TLS receive-path zero-length-list condition that can produce denial of service or memory disclosure; CVE-2025-39964 is an AF_ALG concurrent-write race that can crash the kernel or corrupt cryptographic results; CVE-2026-53266 is an ebtables SNAT ARP-rewrite out-of-bounds write that can cause memory corruption. The relevant federal remediation date is September 21, 2026. CISA has not published exploit mechanics or victim details. Distribution fixes are kernel-build specific: Ubuntu, for example, lists fixed builds for CVE-2025-39682 and CVE-2025-39964, while CVE-2026-53266 remains in a work-in-progress state for some Ubuntu generic kernels and is fixed in certain HWE/26.04 branches. Do not infer that a package is fixed from the CVE number alone; verify the installed kernel and reboot status. Evidence: CISA dated alert, SecurityWeek reporting, CVE records, and Ubuntu security notices. Attribution: unknown. Confidence: high for CVE identity and affected-function descriptions; high for the September 21 action date; low for exploit scope and post-exploitation outcomes. Uncertainty: whether exploitation is limited to local users, containers, or already-compromised hosts in observed cases; exploit code has not been publicly described by CISA. Sources: CISA dated alert, SecurityWeek, CVE Records, and Ubuntu Security Notices.
[AMBER] — Security-software supply chain | Global — CrowdSec confirms source-code exposure through the TanStack compromise path
CrowdSec said September 17 that it learned on September 16 of a GitHub source-code leak that occurred in May 2026. The exposure involved approximately 300 repositories, including more than 170 private repositories and private code for the SaaS console, AWS cloud routines, connectors, and automations. CrowdSec reported no client data, client credentials, login/passwords, names, organizations, or other customer information exposed, and said it found no token or credential enabling lateral movement so far. The company believes the likely vector was the May TanStack compromise: a backdoored package appears to have extracted a CI/CD API key authorized to read the private codebase. CrowdSec rotated required tokens and credentials. Customers should still review integrations, package-lock histories, CI/CD access, and any secrets available to builds during the May window. Fixed version: not applicable; rotate, invalidate, rebuild, and monitor. Evidence: direct CrowdSec statement, corroborated by SecurityWeek. Attribution: likely the TanStack compromise path; actor attribution is not established. Confidence: high for the source-code exposure and CrowdSec’s response; moderate for the precise attack path. Uncertainty: what code was accessed before rotation, whether any downstream customer environments used affected artifacts, and whether the stolen code will be operationalized. Sources: CrowdSec statement and SecurityWeek.
[WATCH] — Developer package supply chain | Global — Rust maintainers and crate owners are being targeted by social engineering
SecurityWeek reported September 21 that the Rust crates.io team and security response working group warned of an ongoing campaign using fake job or contract offers, video calls, counterfeit company profiles, and requests to install a “missing audio codec” or execute clipboard-pasted code. The warning connects the techniques to earlier targeting of Rust developers and the August arrayref crate compromise, but does not identify a specific actor or establish that the current campaign has produced a malicious release. Developers should use trusted meeting platforms, enable MFA, review recent logins and recovery settings, and separate package-release credentials from development workstations. Fixed version: not applicable; this is an identity and release-integrity risk. Evidence: Rust project warning as reported by SecurityWeek. Attribution: no named actor; technique overlap with North Korean activity is not attribution. Confidence: moderate for the campaign warning; low for its current victim count and package impact. Uncertainty: targeted accounts, successful compromises, and whether additional crates are affected. Source: SecurityWeek, “Rust Team Members and Popular Crate Owners Targeted via Video Calls,” September 21, 2026.
Defensive Posture Changes
Control-system integrity
Water operators should validate the physical process and the digital control state together. Remote access should terminate at a monitored gateway or VPN with allowlisted engineering endpoints, not at an exposed PLC or controller. Preserve controller projects, alarm histories, authentication logs, remote-access records, and network telemetry before making broad changes. If controller integrity cannot be proven, use the established safe manual or fallback operating procedure.
Tier-0 orchestration controls
Workflow engines that can run JavaScript, Python, shell commands, or AI-agent tasks belong in the privileged control-plane inventory. For Conductor, upgrade to 3.30.2 or later, restrict the API, remove unauthenticated paths, review workflow definitions created or modified since the first reported exploitation window, and search for unexpected child processes, persistence, cloud metadata access, and outbound connections. Rotate credentials available to the service if any suspicious activity is found.
Kernel closure and compromise assessment
Patch the affected Linux kernel through the supported distribution channel, verify the exact installed build, reboot where required, and confirm the running kernel—not only the package database—is fixed. Investigate local privilege escalation, container breakout, suspicious AF_ALG or netfilter activity, and unexpected crashes or memory-safety symptoms on systems that were reachable by untrusted users or workloads.
Build and release provenance
Freeze or pin high-risk dependency updates while the TanStack and Rust investigations mature. Require lockfile review, signed or otherwise verifiable artifacts, short-lived CI/CD tokens, isolated release runners, and independent review of changes to package maintainers, publishing rights, and workflow automation. Rebuild from trusted source where a compromised developer or package credential may have been present.
Regional and Sector Pulse
North America
The Colorado water incidents add a newly reported example of attempted OT manipulation without a public-service outage. They should not be merged analytically with the July water campaign until operators or investigators establish common infrastructure, tooling, victims, or actor behavior. The practical sector-level risk remains elevated because small utilities can have direct internet, cellular, vendor, or integrator paths into control environments.
Global software and cloud control planes
Orkes Conductor exploitation is a global risk to organizations using workflow automation or AI-agent orchestration, independent of sector. CrowdSec’s disclosure shows the same supply-chain pressure reaching a security vendor’s private code and cloud routines. Rust’s warning reinforces that maintainers and release credentials are operational targets, not merely software-development concerns.
Continuity from the prior briefing
No materially new, independently verified public update was located in this run for the previously reported Siemens S7 targeting, maritime cyber-physical incidents, or Cisco, GitLab, and Acronis exploitation disclosures. They remain remediation and compromise-assessment workstreams; patch completion should not be treated as proof of clean systems.
Vulnerability and Supplier Watchlist
Orkes Conductor
CVE-2026-58138 — affected 3.21.21 through 3.30.1; fixed in 3.30.2. Active exploitation reported. Priority: emergency patch, exposure restriction, and post-exploitation hunt.
Linux kernel
CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 — CISA action set with a September 21 remediation date. Verify distribution-specific fixed builds and reboot state; do not rely on generic kernel-version assumptions.
Cisco identity and email security
CVE-2026-76460 in Cisco Identity Services Engine and CVE-2026-76461 in Cisco Secure Email Gateway remain high-consequence items from the prior run. Confirm fixed Cisco releases, exposure, authentication-path telemetry, and whether the September remediation deadline was met; investigate before closing.
Check Point Security Management
CVE-2026-16232 remains an active-exploitation concern for Internet-accessible Security Management Servers with unrestricted trusted-client settings. The vendor’s mitigation is to restrict management access and trusted clients; affected-release and hotfix decisions must follow the vendor advisory for the deployed R77/R81/R82 branch.
GitLab and Acronis
CVE-2026-85706 in GitLab and CVE-2026-87886 in Acronis Cyber Protect Cloud remain carry-forward compromise-assessment items from the prior briefing. Verify the vendor-fixed release, review exposed administrative/API surfaces, and rotate secrets where exploitation could have preceded patching.
Siemens industrial controllers
The prior warning concerning targeting of Siemens S7 PLCs remains relevant to water and other process operators. Inventory Internet exposure, vendor remote access, cellular paths, engineering workstations, and known-good controller images; no new public technical indicator was independently verified in this run.
Outlook and Uncertainty
Next 24 hours
- Expect additional operator, state, or federal detail on the Colorado water incidents, including affected vendors, access paths, and whether control changes were confirmed from system evidence.
- Monitor FortiGuard, Conductor maintainers, and incident responders for new indicators, victim counts, and evidence of downstream compromise from CVE-2026-58138.
- Expect distribution updates or clearer remediation mapping for the three Linux CVEs as the September 21 action date passes; watch for confirmed exploit mechanics rather than treating reporting language as proof of a common exploit.
- Watch CrowdSec and TanStack-related disclosures for affected artifact versions, CI/CD indicators, and evidence that code exposure led to customer or downstream compromise.
- Monitor Rust project channels for compromised accounts, malicious crate releases, or release-integrity guidance.
What is not known
The Colorado utilities, OT vendors, initial-access vector, persistence, and actor are unknown. No public evidence currently links that event to the July campaign or to a named Iranian group. For Orkes, the number of compromised servers, downstream systems reached, and secrets accessed are unknown. For Linux, CISA has not published exploit mechanics, victim data, or evidence that the three CVEs were used together. For CrowdSec and Rust, the extent of any downstream artifact or credential impact remains unresolved.
Trigger for escalation
Escalate immediately if a water operator confirms unauthorized process changes, loss of alarm integrity, safety impact, or repeated access after containment; if an Orkes instance shows unauthenticated workflow creation, command execution, persistence, or cloud-secret access; if a Linux host shows exploitation or privilege escalation; or if CrowdSec/TanStack/Rust investigations identify customer credentials, malicious releases, or a live propagation path.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Introduction
Today’s briefing prioritizes verified control-plane risk: Colorado water-OT manipulation, active Orkes Conductor exploitation, three Linux kernel entries requiring closure, and fresh software-supply-chain exposure affecting CrowdSec and Rust maintainers.
Search tags
Colorado water OT attack
Linux kernel CISA KEV
CrowdSec source code exposure
TanStack supply chain attack
Rust crate maintainer targeting
critical infrastructure cybersecurity
industrial control systems threat intelligence
Source Register
Colorado water OT incidents
SecurityWeek — “Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems” — September 21, 2026:
https://www.securityweek.com/colorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems/
SecurityWeek’s linked context for prior water-sector OT activity:
https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/
Orkes Conductor CVE-2026-58138
Fortinet FortiGuard — “Orkes Conductor Evaluator Remote Code Execution”:
https://www.fortiguard.com/outbreak-alert/orkes-conductor-rce
Fortinet FortiGuard threat-signal mirror — “Orkes Conductor Evaluator Remote Code Execution” — September 9, 2026:
https://www.fortiguard.com/threat-signal-report/6527/orkes-conductor-evaluator-remote-code-execution
SecurityWeek — “Critical Orkes Conductor Vulnerability Exploited in Attacks” — September 18, 2026:
https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/
CVE Record — CVE-2026-58138:
https://www.cve.org/CVERecord?id=CVE-2026-58138
NIST National Vulnerability Database — CVE-2026-58138:
https://nvd.nist.gov/vuln/detail/CVE-2026-58138
OpenTaint — “CVE-2026-58138: Critical Orkes Conductor RCE”:
https://opentaint.org/blog/conductor-rce-cve-2026-58138
Conductor OSS release v3.30.2:
https://github.com/conductor-oss/conductor/releases/tag/v3.30.2
Linux kernel vulnerabilities and CISA action
CISA dated alert — “CISA Adds Two Known Exploited Vulnerabilities to Catalog” — September 18, 2026:
https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog
SecurityWeek — “Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities” — September 21, 2026:
https://www.securityweek.com/organizations-warned-of-3-exploited-linux-kernel-vulnerabilities/
CVE Record — CVE-2025-39682:
https://www.cve.org/CVERecord?id=CVE-2025-39682
CVE Record — CVE-2025-39964:
https://www.cve.org/CVERecord?id=CVE-2025-39964
CVE Record — CVE-2026-53266:
https://www.cve.org/CVERecord?id=CVE-2026-53266
Ubuntu Security Notice — CVE-2025-39682:
https://ubuntu.com/security/CVE-2025-39682
Ubuntu Security Notice — CVE-2025-39964:
https://ubuntu.com/security/CVE-2025-39964
Ubuntu Security Notice — CVE-2026-53266:
https://ubuntu.com/security/CVE-2026-53266
CrowdSec and TanStack supply chain exposure
CrowdSec — “CrowdSec Statement: Source Code Exposure in May 2026” — September 17, 2026:
https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
SecurityWeek — “CrowdSec Confirms Source Code Stolen in Supply Chain Attack” — September 21, 2026:
https://www.securityweek.com/crowdsec-confirms-source-code-stolen-in-supply-chain-attack/
Rust maintainer and crate-owner targeting
SecurityWeek — “Rust Team Members and Popular Crate Owners Targeted via Video Calls” — September 21, 2026:
https://www.securityweek.com/rust-team-members-and-popular-crate-owners-targeted-via-video-calls/
Carry-forward sources used for prioritization
CISA dated Cisco advance notification — “Cisco Security Vulnerability Policy Update” — September 16, 2026:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP
Check Point Security Advisory — CVE-2026-16232:
https://support.checkpoint.com/results/sk/sk185169/
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: