Skip to content

company

Orca Security

Cloud security vendor whose agentless platform scans cloud accounts and workloads to build an asset inventory and rank the risks it finds.

Known aliases

  • Orca
  • orca.security
  • Orca Security research team

Relationships

No evidence-backed relationships are recorded.

Current stories

security7 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
security4 publishers

Two loops, one blocklist bypass: Elementor Pro's upload field becomes unauthenticated RCE

CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence68
security7 publishers

Attacker copied 170 CrowdSec repositories with a departed employee's still-live GitHub token

CrowdSec kept a leaver's GitHub access open so he could finish some work, his laptop was hit by the TanStack npm compromise on May 11, and the repositories were copied on May 22 and posted to a forum on September 16.

Publishers:crowdsec.netgithub.cominfosecurity-magazine.comold.tanstack.comorca.securitysecurityweek.comthehackernews.com

Perspective Coverage

7 publishers
Builder
Builder 39%
Operator
Operator 52%
Investor
Investor 9%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives65
Confidence60