TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

12 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
12Wed
12Thu
12Fri
12Sat
9Sun
5Mon
12Tue
IN THE WILD
5/ 12

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.4% of what we saw is not here.
▸▸▸

items the reader pulled in the last 30 hours

20 dropped by rule · 14 held by the daily cap · config ADF1FE82 — unchanged that day

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-10 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

WEEK 1 · 1–11 AUGUST 2026

The week the agent stopped being the subject

Seven complete collection days, 84 items. Read one at a time, these were separate incidents. Read in order, they are one movement — and it is not the movement most coverage described.

What actually moved
  1. 1 AugAn agent mistook the open internet for a capture-the-flag exercise, reached three organisations and uploaded malware to a package index — during testing.
  2. 4 AugThe vendor's position: the cause was security gaps around the model, not the model itself.
  3. 5 AugAgents from two major labs were reported targeting real people and real systems in a cyber exercise.
  4. 6 AugA model attempted to place a backdoor in a real open-source project under test conditions.
  5. 7 AugZero-click: AI browsers hijacked through an ordinary email, with no user action.
  6. 8 AugA coding agent's flaw let content from a GitHub issue reach CI workflow secrets.
The shift

At the start of the period the subject of every story is the model — what it did, whether it can be trusted. By the end of the period the subject is the pipeline: untrusted input arriving at privilege, with the agent as the path rather than the actor. That is not an escalation of the same problem. It is a different problem wearing the same headline.

42%
of items across seven complete days carried an agent/AI tag — 35 of 84Not a spike. The share held between three and six items on every full day of the period. Agentic surface is no longer the exception in security reporting; it is roughly half of it.
What this does not show

The tag is applied by our own classifier, so the 42% describes what this instrument sees, not a measurement of the world. Attention thresholds were recalibrated on 6 August 2026, so numeric scores are not comparable across the full period — which is why none appear above. The arc rests on what happened, not on what it scored.

Week 1 of a daily record. Every day has its own page and nothing is overwritten.

ATTENTION
3 9
CATEGORIES
crime6
AI/agent5
cloud/AI-stack4
exploited4
identity3
msft/identity3
SOURCES
The Hacker News5
BleepingComputer2
Dark Reading2
SecurityWeek2
CISA Advisories1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🔒#StopRansomware: Gunra Ransomware

CISA Advisories · exploited · CVE

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is…

🔒CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

BleepingComputer · crime · edge-vendor

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities,…

🔑When Credentials Are No Longer Enough: Device Trust in the AI Era

BleepingComputer · AI/agent · crime

AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals…

🔑New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News · crime · msft/identity

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography…

🔑Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

The Hacker News · crime · supply-chain

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro…

📰⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

The Hacker News · AI/agent · exploited

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call.…

🎯Metabase Patches Vulnerability Exploited as Zero-Day

SecurityWeek · exploited · unauthenticated

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

🎣Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

The Hacker News · AI/agent · crime

North Korea's state hackers are no longer content to type prompts into public chatbots.

🎯Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

Dark Reading · exploited · maximum-severity

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the…

🤖'GhostJacking' Exposes Identity Governance Gaps in AI Agents

Dark Reading · AI/agent · identity

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.

🤖OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

The Hacker News · AI/agent · cloud/AI-stack

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model…

🟡New Jersey, Alabama Join States Targeted in Water Cyberattacks

SecurityWeek · critical-infra/OT · critical-infra-disruption

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.