TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

12 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
4Sun
1Mon
12Tue
12Wed
12Thu
12Fri
12Sat
IN THE WILD
5/ 12

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.4% of what we saw is not here.
▸▸▸

items the reader pulled in the last 30 hours

11 dropped by rule · 10 held by the daily cap · config ADF1FE82 — unchanged that day

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured today from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
4 8
CATEGORIES
AI/agent6
crime6
msft/identity4
patch-or-mitigation4
CVE3
cloud/AI-stack3
SOURCES
The Hacker News6
CISA Advisories2
SecurityWeek2
BleepingComputer1
The Guardian Technology1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🤖New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

The Hacker News · AI/agent · CVE

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every…

📦Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

The Hacker News · AI/agent · crime

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to…

📦Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

The Hacker News · AI/agent · crime

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind…

🩹CPDLC over ATN-B1 Vulnerabilities

CISA Advisories · CVE · critical-infra/OT

View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that…

🎯CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories · exploited · CVE

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…

📦In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

SecurityWeek · AI/agent · crime

Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain…

🎯AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

The Hacker News · AI/agent · exploited

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated…

☁️UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

The Hacker News · crime · cloud/AI-stack

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a…

🎯Metabase SQLi zero-day exploited in customer data-theft attacks

BleepingComputer · exploited · crime

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft…

🤖The White House’s plan to vet potentially dangerous AI is cloaked in secrecy

The Guardian Technology · AI/agent · msft/identity

A Trump administration framework on AI testing leaves a lack of transparency – and plenty of open questions After months of…

🪪Microsoft, Apple Release Fresh Security Updates

SecurityWeek · msft/identity · auth-bypass

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity…

🎣Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

The Hacker News · crime · msft/identity

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs…