NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-08-03 Daily Security Intelligence

7 itemsTop severity 9.8 (Critical)CSSA 1 · CVE 1 · Poisoning 5

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning9.8 Critical

Redis blocking list traversal triggers heap use-after-free leading to remote code execution

The vulnerability lies in the underlying logic that wakes blocked clients. When multiple clients block waiting on the same key, the server iterates the blocked list and resumes client command execution in turn. If the eviction mechanism fires during this process, connection resources for subsequent clients are forcibly released while the iterator still holds references to the freed list nodes, producing a heap use-after-free condition. An attacker can construct a race condition over the network with crafted blocking commands combined with memory threshold configuration, and exploit the memory corruption to hijack control flow without any authentication. Affected systems face arbitrary code execution and process termination, severely disrupting business continuity.

Component
Redis is a high-performance in-memory key-value store built on a single-threaded event-driven architecture with a primary-replica replication model. I…
Type
Use After Free (CWE-416)
Repo
github.com/redis/redis · Stars 75856
Remediation
  • It is recommended to manage dynamic memory lifecycles automatically with smart pointers or reference counting, use snapshot copies or deferred safe deletion when iterating container structures to avoid iterator invalidation, strictly validate object state flags with null and validity assertions before access, and periodically review pointer dereference paths with static analysis to eliminate dangling references.

CVE Intelligence1

CVE-2026-68579CVSS 9.6 Critical2026-08-02

FreeRDP Clipboard Client Heap Buffer Overflow Leading to Remote Code Execution

In FreeRDP prior to 3.30.0 (up to and including 3.29.0), the CliprdrStream_Read function in the Windows clipboard client (client/Windows/wf_cliprdr.c) contains a length validation flaw resulting in a heap-based buffer overflow (CWE-787). When an OLE paste consumer such as explorer.exe calls IStream::Read, the function incorrectly uses the server-supplied length (req_fsize) rather than the caller's buffer size (cb) when copying data. A malicious or compromised RDP server can return an oversized CB_FILECONTENTS_RESPONSE, causing attacker-controlled data to be written out of bounds into the paste consumer's heap buffer and threatening process stability and security. FreeRDP contains a memory corruption vulnerability when a user pastes server-supplied clipboard file content, which an attacker can trigger with a crafted RDP server response, leading to remote code execution or service disruption. The vulnerability affects all FreeRDP users who have not updated to 3.30.0. An attacker needs to induce the target user to paste file content from a malicious RDP server to trigger it.

Component
FreeRDP is an open-source implementation of the Remote Desktop Protocol (RDP) supporting cross-platform connections to Windows Remote Desktop Services, with clipboard sharing and file transfer capabilities.
Risks
  • From standard user to administrator: If the victim runs the FreeRDP client or related processes with administrative privileges, the attacker gains the same privileges
  • Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
  • User interaction required: The attacker must induce the user to paste file content from a controlled malicious RDP server, raising the success rate through social engineering
Source
Remediation
  • Immediately upgrade FreeRDP to version 3.30.0 or later to fix the vulnerability
  • Avoid pasting file content from untrusted or unverified RDP servers
  • Enable sandbox isolation for environments running FreeRDP to limit the reach of potentially malicious code

Package Poisoning5

Package Poisoningnpm2026-08-03

list-issue-predecessor-dependencies-block@99.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
dfb5e80dd43ee9ea077e9cc4a69e407c
Package Poisoning2026-08-03

@ flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
fa137382802a68fe51a1e058d45c5318
Package Poisoning2026-08-03

@ flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
aaa5fed6de167bb047ecb3c728d1b7c0
Package Poisoning2026-08-03

@ flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4ca2180acfbe83332ca5a872abdfad39
Package Poisoning2026-08-03

@ flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
2e6bf5fbd1d4aa545743d46f6e468587