Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
items the reader pulled in the last 30 hours
The digest hands us counts, not the discarded items — so this shows how many and why, not which.
July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.
All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.
And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.
Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.
Attention classes are how much attention we gave an item. They are not severity verdicts.
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting…
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and…
Agent found to be able to find and exploit vulnerabilities without human intervention, and to carry out cyber-attacks OpenAI…
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user…
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to…
Exclusive: anonymous flagging service says cases have surged, as watchdog says AI is making sexualised or ‘nudified’ content…
Observers express concern that the division has lost its independence and commercial reality has taken over When Sir Demis…