NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-09-01 Daily Security Intelligence

14 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 2 · Poisoning 10

CSSA Exclusive Early Warning2

CSSA Exclusive Early Warning10.0 Critical

AgentScope Bash tool permission bypass from incomplete command-separator validation damaging system integrity and availability

An attacker exploits incomplete command-separator recognition in is_read_only_command by crafting malicious compound commands containing & or newlines, so dangerous operations such as file deletion that should be blocked are misclassified as read-only. That triggers check_permissions' fast-allow path, skipping later security checks and user confirmation, creating arbitrary code execution risk and directly threatening system integrity and data availability in the controlled environment.

Component
AgentScope is an open-source framework for building large language model agents. Its core architecture aims to enable modular construction and efficie…
Type
Incomplete List of Disallowed Inputs (CWE-184)
Repo
Remediation
  • Complete the command-separator allowlist to cover all valid separator cases, perform strict AST deep-traversal analysis before execution so every subcommand meets the read-only standard, and introduce mandatory human review to block automated high-risk operations.
CSSA Exclusive Early Warning10.0 Critical

OpenRLHF remote reward model service missing authentication leading to training signal tampering and data disclosure

An attacker can abuse the default 0.0.0.0 bind and unauthenticated POST /get_reward endpoint to inject malicious reward values within network reach, steering policy updates while stealing prompts and generated text from request payloads, resulting in manipulated model training and sensitive data exfiltration.

Component
OpenRLHF is a reinforcement learning from human feedback framework. Its core architecture includes distributed policy optimization components and a re…
Type
Missing Authentication for Critical Function (CWE-306)
Repo
Remediation
  • Change the default listen address to the local loopback interface, mandate mutual TLS or shared-secret authentication, and validate format and integrity of returned reward values so only trusted sources can enter the training loop.

CVE Intelligence2

CVE-2026-82693CVSS 10.0 Critical2026-08-31

Tenda AC1206 Web UI Telnet feature missing authentication leading to remote unauthorized access

In Tenda AC1206 version 15.03.06.23, the TendaTelnet function in /goform/telnet of the Web UI component has an improper authentication (CWE-287) security defect. Performing specific operations causes authentication to be missing, and an attacker can launch the attack remotely. The exploitation method has been publicly disclosed and is at risk of being used. The Tenda AC1206 router has a serious security vulnerability in Web UI interaction scenarios; an attacker can trigger it with crafted requests, leading to remote unauthorized access or full device control. It affects all Tenda AC1206 users running firmware 15.03.06.23. An attacker only needs to send crafted requests over the network, with no user interaction required, for remote control.

Component
Tenda AC1206 is a home wireless router providing Wi-Fi connectivity and network management; its Web UI is used to configure device parameters.
Risks
  • From ordinary user to administrator: If exploitation succeeds, an attacker can obtain Telnet access to the device and thus administrator-level control
  • Complete system control: An attacker can execute arbitrary commands on the router and, depending on privileges, modify network configuration, view/change/delete data or create fully privileged accounts
  • No user interaction required: Via remote network requests (T1190), an attacker only needs to send malicious packets to the target device, with no further user interaction
Source
Remediation
  • Monitor anomalous network connections and Telnet access logs
  • Enable strong authentication on the router management interface or restrict source IPs
  • Block requests to the /goform/telnet endpoint from untrusted sources
CVE-2026-82695CVSS 10.0 Critical2026-08-31

Tenda AC18 Telnet Handler authentication bypass leading to remote code execution

In Tenda AC18 version 15.03.05.19, a logic defect in an unknown function in /goform/telnet of the Telnet Handler component creates an improper authentication (CWE-287) security defect. The manipulation causes authentication to be missing, and an attacker can attack remotely. Exploit code has been disclosed and may be used in attacks. The Tenda AC18 router has an authentication bypass in specific Telnet access scenarios; crafted requests can trigger unauthorized remote access or system control. It affects all unpatched Tenda AC18 15.03.05.19 users. An attacker only needs to send specific requests remotely, with no user interaction, for remote control.

Component
Tenda AC18 is a home wireless router providing Wi-Fi connection management and network configuration; the Telnet Handler component processes remote terminal connection requests.
Risks
  • From ordinary user to administrator: If authentication is bypassed, an attacker can obtain full administrative control of the router
  • Complete system control: An attacker can execute arbitrary commands on the router, modify network configuration, steal sensitive data or plant backdoors
  • No user interaction required: An attacker needs no victim action and can trigger the vulnerability by sending malicious packets remotely
Source
Remediation
  • Disable the Telnet service in the router management UI and switch to the more secure SSH protocol
  • Configure firewall rules to restrict remote access to the /goform/telnet endpoint

Package Poisoning10

Package Poisoningnpm2026-09-01

selfsigned-certificate@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
41572c2f306b507b0d49a0ab4af4c2a9
Package Poisoningnpm2026-09-01

tailwindcss-forms-style@0.1.2 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
0de57f3d76d56d34763bf2460d3cd7d7
Package Poisoningnpm2026-09-01

kisama-js@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
2aca2fd098e55351257c2c1f5af62d9e
Package Poisoningnpm2026-09-01

@yane88/hexhub-client@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
3eaf1d84210daff9fb1c720213582ced
Package Poisoningnpm2026-09-01

@yane88/idea-2026.2-06@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
1b97166bbdfdd94a22b372908b7fc37a
Package Poisoningnpm2026-09-01

@yane88/listary-02@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
d8fdedf6dad0b58e49069f769c473a30
Package Poisoningnpm2026-09-01

@yane88/term-reqable-02@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
78edf93d8f9a7d96f0c3502ef0fb3314
Package Poisoningnpm2026-09-01

@yane88/workbuddy@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
09788403514ae706e2c30a786c3c4e3f
Package Poisoningnpm2026-09-01

@yane88/workbuddy-02@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
c77c49d2cfac1e5f6c3edf4d27b35b14
Package Poisoningnpm2026年09月01

core_main@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
fbe22731b1428483ba281605625a8b75