TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

9 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
1Mon
12Tue
12Wed
12Thu
12Fri
12Sat
9Sun
IN THE WILD
5/ 9

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.5% of what we saw is not here.
▸▸▸

items the reader pulled in the last 30 hours

2 dropped by rule · 0 held by the daily cap · config ADF1FE82 — unchanged that day

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-09 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
2 2 5
CATEGORIES
AI/agent6
cvss-critical2
exploited2
CVE1
cloud/AI-stack1
crime1
SOURCES
The Hacker News4
The Guardian Technology3
BleepingComputer1
SecurityWeek1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

The Hacker News · exploited · cvss-critical

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization…

🎯Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The Hacker News · exploited · CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting…

🤖Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

SecurityWeek · AI/agent · msft/identity

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and…

🤖OpenAI to pause some work on AI model Astra due to security concerns

The Guardian Technology · AI/agent · cloud/AI-stack

Agent found to be able to find and exploit vulnerabilities without human intervention, and to carry out cyber-attacks OpenAI…

🤖Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

The Hacker News · AI/agent

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user…

🤖New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

The Hacker News · AI/agent

New research shows content inside an email can escape its message boundary and interfere with the webmail interface.

💧Hackers breach TrueConf to trojanize client installers with backdoors

BleepingComputer · crime · patch-or-mitigation

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to…

🤖Rising number of UK children report seeing explicit deepfakes of themselves

The Guardian Technology · AI/agent

Exclusive: anonymous flagging service says cases have surged, as watchdog says AI is making sexualised or ‘nudified’ content…

🤖Google DeepMind enters a new era as co-founder Demis Hassabis shifts AI role

The Guardian Technology · AI/agent

Observers express concern that the division has lost its independence and commercial reality has taken over When Sir Demis…