Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
items the reader pulled in the last 30 hours
The digest hands us counts, not the discarded items — so this shows how many and why, not which.
July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.
All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.
And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.
Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.
Attention classes are how much attention we gave an item. They are not severity verdicts.
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every…
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to…
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind…
View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain…
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated…
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a…
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft…
A Trump administration framework on AI testing leaves a lack of transparency – and plenty of open questions After months of…
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity…
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs…