NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
RSS

2026-09-29 Daily Security Intelligence

CVE Intelligence 2

CVE-2026-73640 CVSS 10.0 Critical 2026-09-28

Dayforce Payroll password recovery time-based blind SQL injection vulnerability leads to unauthorized data disclosure

In Dayforce Payroll R2026.2.0, the password recovery feature contains a time-based blind SQL injection (CWE-89) security flaw due to missing input validation. An unauthenticated attacker can craft a specific GET request with a parameter containing an arbitrary SQL query. The parameter is interpreted as part of an SQL predicate, resulting in time-based blind SQL injection. Attempts to contact the vendor were unsuccessful, so the vulnerability has only been confirmed in R2026.2.0, although other versions may also be affected. An attacker can exploit it remotely without authentication and infer database contents from time delays, potentially exposing sensitive payroll data or compromising system integrity.

Component
Dayforce Payroll is enterprise human resources and payroll management software used to handle employee compensation, taxes, and compliance matters.
Risks
  • Unauthorized access: An attacker needs no credentials to launch an attack and can probe the password recovery endpoint directly
  • Data disclosure: Using time-based blind SQL injection, an attacker can progressively extract sensitive database information, such as employee salaries and personally identifiable information (PII)
  • Complete system control: If combined with other vulnerabilities or misconfigurations, an attacker may execute further arbitrary SQL commands, resulting in data modification or deletion
  • No-user-interaction attack: The attack arises entirely from a flaw in server-side processing logic and requires no clicks or interaction from the victim
Source
Remediation
  • Deploy SQL injection detection rules in the Web application firewall (WAF), particularly for time-delay attacks
  • Apply strict allowlist validation to input parameters on the password recovery endpoint and use parameterized queries
  • Monitor abnormal server response times to identify potential blind SQL injection attacks
CVE-2026-86102 CVSS 10.0 Critical 2026-09-29

WatchGuard AP internal API service OS command injection vulnerability leads to remote code execution

The internal API service of WatchGuard AP contains an operating system command injection (CWE-78) security flaw due to missing input validation. An attacker with network access to the AP can send a crafted request to the internal API and execute arbitrary shell commands on the underlying operating system. The vulnerability allows an attacker with network access to take complete control of the affected device. It affects all unpatched WatchGuard AP devices. An attacker only needs a network connection to trigger the vulnerability, with no user interaction, and can control the device remotely.

Component
WatchGuard AP is a wireless access point device from WatchGuard that provides enterprise wireless network coverage and management capabilities.
Risks
  • From ordinary user to administrator: If an attacker successfully exploits this vulnerability, they can gain full control of the underlying operating system, equivalent to administrator privileges
  • Complete system control: An attacker can exploit this vulnerability to execute arbitrary code on the victim system and, depending on user privileges, install programs, view, modify, or delete data, or create new accounts with full privileges
  • No-user-interaction attack: Through direct network access (T1190), an attacker only needs to send a malicious request to the AP to trigger the vulnerability, with no additional interaction
Source
Remediation
  • Monitor abnormal request logs for the AP internal API service
  • Enable network access-control list (ACL) restrictions on the AP management interface
  • Block API calls from untrusted sources

Package Poisoning 9

Package Poisoning npm 2026-09-29

img-to-native@>= 0 flagged as malicious

The component was found to contain malicious code that decrypts and drops an attacker-controlled Windows executable when require() is called.

MD5
405ffe9d72bffc2bdf215eb26c371a74
Package Poisoning npm 2026-09-29

native-runner@>= 0 flagged as malicious

The component was found to poll for and launch an external binary at a hardcoded path in a hidden, detached process when it is loaded with require.

MD5
db1f4113565b16372699c9366d26ffbd
Package Poisoning npm 2026-09-29

nebula-sdk@>= 0 flagged as malicious

The component was found to embed and execute a decoded malicious Windows PE executable disguised as conhost.exe through the preinstall.cjs lifecycle script. This behavior is consistent with native RAT family tools, and a computer on which it has been installed should be considered fully compromised.

MD5
e50bfb3b240b272c8aeb8ef9b881bad3
Package Poisoning npm 2026-09-29

nebulajs-api@>= 0 flagged as malicious

The component was found to contain a custom PRNG-based string decoder and a ciphertext table, reconstructed into executable code through XOR at runtime. This is a typical npm install-time RCE dropper pattern, and any computer on which this package has been installed or run should be considered fully compromised.

MD5
8862eee35c5bd066b01f32971a82f8e1
Package Poisoning npm 2026-09-29

vite-plugin-crypto@>= 0 flagged as malicious

The component was found to concatenate option fields and pass them to the SystemJS runtime module loader, enabling arbitrary JavaScript execution on the Vite build/development host. Any computer on which this package has been installed or run should be considered fully compromised.

MD5
450eab40241f04fe4e7b421d7a884bd6
Package Poisoning npm 2026-09-29

llm-nebula@1.0.0 flagged as malicious

The component was found to masquerade as an LLM SDK while executing an obfuscated malicious payload at installation time through a preinstall hook.

MD5
8c98e43eb1e05225de8e7ad791d55aaf
Package Poisoning npm 2026-09-29

hardhat-zet@2.0.1 flagged as malicious

The component was found to have been published under a name impersonating the Hardhat Ethereum tooling ecosystem. Its README and documentation were copied from the unrelated pino logging project, and its main entry file contains a 4,498,609-byte obfuscator.io-style obfuscated bundle that executes automatically when loaded with require. It is suspected to be a supply-chain information stealer targeting Ethereum developers.

MD5
1335aafb0c6ba8927020006b8776fcbb
Package Poisoning npm 2026-09-29

items-validator@1.0.5 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
19d133ccf0c9d33e695ba89b6ab3cc83
Package Poisoning PyPI 2026-09-29

aseitylab@0.1.0 flagged as malicious

The component was found to contain malicious code that executes an arbitrary payload obfuscated with base85/zlib during installation or import, as well as an information stealer that retrieves instructions from blockchain C2.

MD5
b2b68cfb4168a9fa452abda543fafc2e