NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-08-06 Daily Security Intelligence

8 itemsTop severity 10.0 (Critical)CSSA 1 · CVE 1 · Poisoning 6

CSSA Exclusive Early Warning1

CSSA Exclusive Early Warning10.0 Critical

OneUptime SAML component XML instruction injection leading to identity forgery and unauthorized access

The vulnerability originates in anomalous transformation logic in the underlying cryptographic library during document canonicalization, which converts embedded processing instructions directly into plain text. An attacker can send a crafted signed response message over the network and, exploiting the difference between the original parsing mechanism and the signature baseline, covertly insert instructions inside a valid signature to tamper with identity fields. This path requires no prior authentication to trigger, breaks the verification logic and allows an unauthorized entity to obtain a high-privilege token.

Component
OneUptime is an open-source system monitoring platform for operations teams and enterprise users. Its core architecture uses a modular design integrat…
Type
Improper Verification of Cryptographic Signature (CWE-347)
Repo
Remediation
  • It is recommended to extract fields strictly from a canonicalized data structure when parsing cryptographic messages, filter out illegal processing instruction nodes, and apply allowlist validation during verification. The parsing context must also be kept consistent with the cryptographic computation baseline, addressing this class of defect at the architectural level.

CVE Intelligence1

CVE-2026-61486CVSS 9.8 Critical2026-08-05

Apache Lucy Stack Buffer Overflow Leading to Remote Code Execution

In all versions of Apache Lucy, the core processing module contains a stack-based buffer overflow (CWE-121). Because the project has reached end of maintenance, no official release will fix this issue. An attacker can send a crafted request remotely over the network to trigger the stack overflow, overwriting memory and threatening process stability and security. Apache Lucy contains a memory corruption vulnerability when processing certain input, which an attacker can trigger remotely with no user interaction, leading to remote code execution or service disruption. The vulnerability affects every deployed Apache Lucy instance regardless of version. An attacker only needs network access to the affected instance to exploit it, requiring no user interaction and allowing remote control.

Component
Apache Lucy is an open-source full-text search engine library designed to provide high-performance text search capability.
Risks
  • From standard user to administrator: If the victim runs the service with administrative privileges, the attacker gains the same privileges
  • Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
  • No user interaction required: The attack is launched directly over a network vector (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N)
Source
Remediation
  • Identify and migrate to a supported alternative search engine
  • Strictly restrict access to instances to trusted users or internal networks
  • Deploy network-layer firewall rules to block requests from untrusted sources

Package Poisoning6

Package Poisoningnpm2026-08-06

chai-foundry@7.0.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
b19cc202976826d547fd62293d46f56c
Package Poisoningnpm2026-08-06

kepler@5.0.999 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
9f2fd80a283e33a61cc00686d88a317c
Package Poisoningnpm2026-08-06

llm-interceptor@0.3.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
3271687a472a5e671ab3e2eced8ffc25
Package Poisoningnpm2026-08-06

claude-remote-agent@0.1.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
8af4340c1db9d98afd88702d4b56c714
Package Poisoningnpm2026-08-06

npm-dc-dev@1.1.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
22adfc3df61440722c5bb67f680628a9
Package Poisoningnpm2026-08-06

statist-browser-typed-client-sme.rko.tariffs.web@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
a51ee7fb5e6f95f1ec381ab764f72b8a