Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
Attention classes are how much attention we gave an item. They are not severity verdicts.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known…
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam…
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four…
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in…
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according…
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source…
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source…
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to…
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations…