Weekly review

ThreatNoir Weekend Brief — August 9

2026-08-09Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — August 9, 2026

The security landscape continues to face mounting threats as critical vulnerabilities in widely-used platforms and supply chain attacks escalate in sophistication. Today's briefing covers zero-day exploits affecting business intelligence tools, a massive malicious package campaign targeting open-source ecosystems, and serious flaws in both WordPress and Linux infrastructure that demand immediate patching.

Metabase SQLi Zero-Day Exploited in Customer Data-Theft Attacks

A critical SQL injection vulnerability in Metabase has been actively exploited in zero-day attacks to breach customer instances and steal sensitive data. The attacks have been confirmed to impact Framework and Tally, two organizations whose customer data was compromised through this vulnerability. Source: Framework and Tally Disclose Metabase Data Theft Attacks

The exploitation of this Metabase flaw represents a significant threat to organizations running vulnerable instances of the business intelligence platform. Companies relying on Metabase for analytics and reporting should immediately assess their deployment status and apply security patches to prevent unauthorized data access.

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Researchers have identified a coordinated campaign distributing nearly 800 malicious packages through the npm registry, all designed to deliver a powerful remote access trojan and information stealer targeting Windows, Mac, and Linux systems. The packages employ AI-generated or randomly-generated typo-squatting names to evade detection while delivering payloads including Sliver and WEL1DROPPER malware. Source: Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

This supply chain attack demonstrates the vulnerability of open-source ecosystems to large-scale infiltration efforts. The identified command and control infrastructure includes domains such as wel1.ru, cloudpayments.ru, and tcsbank.ru, along with several workers.dev subdomains. Developers should audit their project dependencies immediately and remove any packages from this malicious cluster to prevent system compromise.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

WordPress has patched a critical pre-authentication reflected cross-site scripting vulnerability affecting all versions of the content management system. Tracked as CVE-2026-64638 with a CVSS score of 8.9, this flaw exists in the login screen and can be chained to achieve PHP code execution on vulnerable servers. The vulnerability requires no attacker privileges to exploit. Source: New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

Given the severity of this vulnerability and its presence in every WordPress version, immediate patching is essential for all WordPress installations. The combination of pre-authentication access and potential code execution makes this a critical risk for website operators and hosting providers alike.

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free vulnerability in Linux's SCTP networking subsystem has persisted since 2008 and can be exploited by local users to achieve full root access on a host system. Researchers at Tencent have demonstrated successful container escape attacks using this flaw, breaking out from containerized environments to reach the underlying host machine. The vulnerability has been fixed in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148, released on August 3. Source: 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Organizations running older Linux kernels with SCTP functionality exposed should prioritize kernel updates immediately. The extended lifecycle of this vulnerability and its demonstrated capability for container escape pose significant risks to containerized infrastructure and multi-tenant environments.

The convergence of these critical vulnerabilities across multiple platforms underscores the importance of maintaining current patch levels and conducting thorough security assessments of both proprietary and open-source components within organizational infrastructure.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Malware2
  • Sliver
    Open-source C2 framework deployed on Linux
  • WEL1DROPPER
    Name of the initial downloader malware
Domain10
  • cloudpayments.ru
    Potential target domain found in macOS payload
  • oob-worker.cf103-070.workers.dev
    Cloudflare Workers domain for initial payload download
  • oob-worker.cf102-baf.workers.dev
    Cloudflare Workers domain for initial payload download
  • oob-worker.cf99-9b3.workers.dev
    Cloudflare Workers domain for initial payload download
  • wel1.ru
    Fallback domain for next-stage payload delivery via DNS TXT records
  • sdk.dl.wel1.ru
    Linux x64 payload delivery domain
  • ext.dl.wel1.ru
    Linux ARM64 payload delivery domain
  • pkg.dl.wel1.ru
    macOS payload delivery domain
  • net.dl.wel1.ru
    Windows payload delivery domain
  • tcsbank.ru
    Potential target domain found in macOS payload