NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-08-27 Daily Security Intelligence

13 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 2 · Poisoning 9

CSSA Exclusive Early Warning2

CSSA Exclusive Early Warning9.9 Critical

kafka-ui remote code execution by bypassing Groovy filtering leading to full server compromise

An attacker exploits the PUT /api/smartfilters/testexecutions endpoint's failure to check the filtering.groovy.enabled configuration, submitting requests that contain malicious Groovy scripts. Because the executeSmartFilterTest method in MessagesController lacks security interception logic, an attacker without administrator privileges can directly compile and execute arbitrary OS commands, fully taking over the host and sensitive data.

Component
kafka-ui is a visual monitoring and management platform designed for Apache Kafka clusters. Its architecture integrates RESTful API interfaces to prov…
Type
Protection Mechanism Failure (CWE-693)
Repo
Remediation
  • It is recommended to uniformly invoke a security configuration check when handling smart-filter test requests so that the global disable policy takes effect, and to strengthen interface authentication with role-based access control to prevent unauthorized users from triggering code execution.
CSSA Exclusive Early Warning10.0 Critical

Zephyr RTOS USB Bluetooth HCI module out-of-bounds write due to missing bounds checks leading to system crash or memory corruption

An attacker can trigger the vulnerability by sending malicious HCI packets that exceed the USB endpoint Maximum Packet Size (MPS). Because bt_hci_tx_sync_in does not verify that the packet length fits the fixed-size USB transfer buffer, net_buf_add_mem performs an out-of-bounds write. With assertions enabled this causes an immediate system panic; otherwise adjacent memory is overwritten, potentially hijacking control flow, leaking sensitive information and making the service unavailable.

Component
Zephyr is an open-source real-time operating system (RTOS) for resource-constrained environments. Its core architecture supports low-power embedded de…
Type
Out-of-bounds Write (CWE-787)
Repo
Remediation
  • Developers should strictly validate source data length against remaining destination buffer space before copying, ensure the allocated limit is never exceeded, introduce a dynamic buffer pool or hardcoded length checks, and enable configuration options that strengthen runtime bounds detection.

CVE Intelligence2

CVE-2026-12717CVSS 9.8 Critical2026-08-26

Google Cloud BigQuery CData JDBC driver improper input validation leading to remote code execution and privilege escalation

In Google Cloud BigQuery Data Transfer Service versions on Google Cloud Platform prior to 2026-05-01, the CData JDBC driver integration has an improper input validation (CWE-74) security defect. An authenticated attacker can craft malicious JDBC connection string parameters to achieve remote code execution inside the connector container and escalate privileges within the tenant project. The vulnerability allows unauthorized arbitrary code execution and seriously threatens data integrity and system control in the cloud environment. It affects all Google Cloud BigQuery Data Transfer Service users who have not updated to a version after 2026-05-01. The attacker needs some authentication, but once exploitation succeeds they can execute code in the container and move laterally to escalate privileges.

Component
Google Cloud BigQuery Data Transfer Service is a Google Cloud Platform service that automatically transfers data from various sources into BigQuery, integrating the CData JDBC driver to support connections to many data sources.
Risks
  • Remote code execution: An attacker can execute arbitrary code in the connector container and fully control the container environment
  • Privilege escalation: An attacker can escalate privileges in the tenant project and then access or modify other sensitive resources
  • Data disclosure and tampering: With elevated privileges, an attacker may steal, tamper with or delete critical business data in BigQuery
Source
Remediation
  • Confirm the service version has been updated to 2026-05-01 or later, which fixes this vulnerability
  • Review and restrict the input sources for JDBC connection string parameters and enforce strict input validation
  • Monitor connector container anomaly logs to detect potential malicious execution activity
CVE-2026-77537CVSS 10.0 Critical2026-08-26

UniFi Protect command injection leading to remote code execution

In the UniFi Protect application, improper input validation (CWE-20) creates a command injection security defect. An attacker with network access can exploit it to execute arbitrary commands on the host device. The vulnerability allows a direct network-based attack with no user interaction and low attack complexity, and may seriously damage confidentiality, integrity and availability of the host system. It affects all unpatched UniFi Protect deployments; an attacker needs only network access to trigger remote code execution.

Component
UniFi Protect is video surveillance system software from Ubiquiti Networks for managing network cameras, recorders and related security devices.
Risks
  • Complete system control: An attacker can execute arbitrary commands on the host device and fully control the affected system
  • High-privilege escalation: If the service runs with elevated privileges, an attacker may obtain the highest system privileges, then access sensitive data or install malware
  • No user interaction required: An attacker needs no user action and can attack over the network alone, making it highly stealthy
Source
Remediation
  • Restrict access to the UniFi Protect management interface at the network layer, allowing only trusted IP addresses
  • Deploy an intrusion detection system (IDS) or firewall rules to monitor and block anomalous command-execution traffic

Package Poisoning9

Package Poisoningnpm2026-08-27

svelte-vli-ui@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
cda319748517bff26b55be963f700542
Package Poisoningnpm2026-08-27

self-certificates@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d71d53732effd00a0718baf59e6bf598
Package Poisoningnpm2026-08-27

self-sign@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
a352f9a9aded15e30840e86d9c87fafc
Package Poisoningnpm2026-08-27

dumb-binding-gyp-package@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
15c0474d23441126c9bf13c0117a90ef
Package Poisoningnpm2026-08-27

grandfather_of_the_desert@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
f427241ba3e5cbd94d8e01e9294fa223
Package Poisoningnpm2026-08-27

shai_hulululud@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
31cfb382c3dcece40aabe7f8b85bfa14
Package Poisoningnpm2026-08-27

the_tax_free_cashier_is_at_9f@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
3472880c17512c02fe171ef9502f9fb5
Package Poisoningnpm2026-08-27

tset_racie@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
459f6fcb186ce81cb32ac1581a12277a
Package Poisoningnpm2026-08-27

bnotify-web-sdk@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
5ad638063be6709776dafd4a120b1b40