NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
RSS

2026-10-09 Daily Security Intelligence

CSSA Exclusive Early Warning 1

CSSA Exclusive Early Warning 8.5 High

Unchecked symbolic link targets in the Ouch archive extraction tool pose a risk of arbitrary file writes

An attacker can craft an archive containing malicious symbolic links and use links pointing outside the root directory to perform unauthorized writes when a user extracts it. Older versions lack strict validation that symbolic link targets remain within the extraction root and allow later entries to overwrite symbolic links created by earlier entries. This compromises file system integrity and may lead to configuration tampering or privilege escalation.

Component
Ouch is an efficient command-line archive tool written in Rust. Its core functions include creating and extracting mainstream archive formats such as tar and zip, with the aim of providing fast and secure local file management. By parsing archive metadata and reconstructing file structures, the component supports system-level data backup and software distribution.
Type
Improper Link Resolution Before File Access (CWE-59)
Repo
Remediation
  • Upgrade to the latest stable version containing the security patch. Ensure that all symbolic link target paths undergo strict allowlist validation and root directory isolation checks during extraction, and prohibit unauthorized writes to external files to block these escape attacks.

CVE Intelligence 2

CVE-2026-106126 CVSS 9.9 Critical 2026-10-09

Command injection in Tenable Identity Exposure allows remote code execution with SYSTEM privileges

The Active Directory Events Listener component of Tenable Identity Exposure (SaaS) contains a command injection flaw caused by improper neutralization of special elements used in operating system commands (CWE-78). An authenticated attacker with low privileges can exploit the vulnerability to execute arbitrary commands with SYSTEM privileges on the PDCe (primary domain controller emulator). The attack can be launched over the network with low complexity and no user interaction. Successful exploitation severely affects confidentiality, integrity, and availability. All unpatched Tenable Identity Exposure deployments are affected. An attacker only needs a low-privilege account to trigger the vulnerability and obtain the highest system privileges.

Component
Tenable Identity Exposure is a SaaS-based identity security platform that monitors and analyzes identity-related events in Active Directory to help organizations detect anomalous behavior and potential threats.
Risks
  • Privilege escalation: An attacker can escalate directly from a low-privilege account to the highest SYSTEM privileges, completely bypassing access controls
  • Complete system control: An attacker can execute arbitrary commands on the PDCe, leading to data disclosure, tampering, or destruction, and potentially control of the entire domain environment
  • Remote exploitation: The attack takes place over the network without physical access or complex user interaction, making it easy to automate
Source
Remediation
  • Strictly restrict network access to Active Directory Events Listener and enforce the principle of least privilege
  • Monitor abnormal command execution on the PDCe and deploy an intrusion detection system to identify potential command injection attacks
CVE-2026-77900 CVSS 9.8 Critical 2026-10-09

Missing authentication for a critical function in Azure App Service allows remote code execution

Azure App Service contains a missing authentication for critical function flaw (CWE-306) because critical functions lack an authentication mechanism. An unauthorized attacker can execute code directly over the network, threatening the service's confidentiality, integrity, and availability. An authentication bypass vulnerability exists in Azure App Service under certain function invocation scenarios. An attacker can trigger it without any credentials, leading to remote code execution or data disclosure. All unpatched Azure App Service instances are affected, including cloud deployments. An attacker only needs to send a crafted request over the network to exploit the vulnerability, with no user interaction required, and can gain remote control.

Component
Azure App Service is a fully managed Web application hosting service provided by Microsoft's Azure cloud platform. It supports multiple programming languages and frameworks for building and hosting Web applications, mobile backends, and REST APIs.
Risks
  • Complete system control: An attacker can exploit the vulnerability to execute arbitrary code on an affected Azure App Service instance and gain control of the server
  • Data disclosure and tampering: With high impacts on confidentiality, integrity, and availability, an attacker can read, modify, or delete sensitive data
  • Unauthenticated remote attack: An attacker needs no authentication credentials and only requires network access to launch an attack, with low exploitation difficulty
Source
Remediation
  • Immediately review and update Azure App Service configuration to ensure that strong authentication is enabled for critical functions
  • Monitor network traffic and block abnormal requests from unknown sources
  • Enforce the principle of least privilege and limit the service's exposed attack surface

Package Poisoning 7

Package Poisoning npm 2026-10-09

@dransay/logger@99.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
3131a04093e8dd025efc4d39dd8ed235
Package Poisoning npm 2026-10-09

@dransay/phone-fix-test@99.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
a881fd667c43fdd6bcd1b29c22977d9d
Package Poisoning npm 2026-10-09

@dransay/secrets@99.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
1aaa2a214bdc592973491a0ff3352ad2
Package Poisoning npm 2026-10-09

dransay@99.0.0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
0277db6c1b1659d22ac67625744a6a6a
Package Poisoning npm 2026-10-09

@kxafunc/xbails@0.0.8 flagged as malicious

Through package.json, the component aliases the libsignal dependency to a mutable latest version from a nonstandard publisher. The lack of version pinning and integrity checks allows an attacker to execute arbitrary code in the Signal end-to-end encryption path and access identity keys, prekeys, and plaintext messages.

MD5
508b193b3530fa3444d807e88a9ee55f
Package Poisoning PyPI 2026-10-09

kafka-helmsman@99.0.1 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
95fd10a2179b8c31d0de2cbd8913de78
Package Poisoning PyPI 2026-10-09

kafka-roller@99.0.3 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
30994965a6dd99afd2524950348c33da