Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.
All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.
And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.
Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.
Attention classes are how much attention we gave an item. They are not severity verdicts.
N-able N-central (CVE-2026-18577) Deadline: CISA zařadila auth bypass zranitelnost do KEV a stanovila federální deadline na…
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model…
US Critical Infrastructure / Water Utilities Cyber Attacks: Útoky na americké vodárny v 30+ státech, přetrvává podezření na…
Follow today’s news live Get our breaking news email , free app or daily news podcast Police say the remains found in a…
Finance sector will gain from the tech but it will need substantial investment and create risks, says rating agency The…