TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

12 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
9Sun
5Mon
12Tue
12Wed
12Thu
12Fri
12Sat
IN THE WILD
2/ 12

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.4% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

11 dropped by rule · 4 held by the daily cap · config F0A70F47 — unchanged since 2026-08-14

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
6 6
CATEGORIES
AI/agent4
AI/agent Gates: attention_class=GREEN | publication_severity=GREEN3
crime3
cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW2
code-execution2
patch-or-mitigation Gates: attention_class=RED | publication_severity=YELLOW | classification_divergence.kind=threshold_policy_split2
SOURCES
BleepingComputer4
SecurityWeek4
Dark Reading3
The Guardian Technology1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🤖The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

BleepingComputer · AI/agent · crime

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive,…

☁️Max severity SAP Commerce Cloud flaw now targeted in attacks

BleepingComputer · cloud/AI-stack · maximum-severity

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted…

🎯Hackers Exploiting Unpatched GeoServer Zero-Day

SecurityWeek · exploited · code-execution

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.

🤖Cyera's Oasis Security Buy Is All About AI Agent Control

Dark Reading · AI/agent · identity Gates: attention_class=YELLOW | publication_severity=YELLOW

The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged…

🤖How Anthropic plans to watermark Claude's AI-generated text

BleepingComputer · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post…

🤖Secondhand booksellers in UK and Ireland suspect AI firms behind ‘strange’ bulk orders

The Guardian Technology · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

Development comes after Anthropic was found to have spent millions on books to scan for ‘data acquisition’ Secondhand…

💧Over 1,000 Charities Hit by Beacon CRM Data Breach

SecurityWeek · crime · cloud/AI-stack Gates: attention_class=GREEN | publication_severity=GREEN

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available…

🌐AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

SecurityWeek · crime · malware-control Gates: attention_class=GREEN | publication_severity=GREEN

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari…

🤖In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

SecurityWeek · AI/agent Gates: attention_class=GREEN | publication_severity=GREEN

Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT…

🤖Mission-Driven Security: Inside a Global Bank's Defense

Dark Reading · AI/agent Gates: attention_class=GREEN | publication_severity=GREEN

In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic…

🤖Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Dark Reading · AI/agent Gates: attention_class=GREEN | publication_severity=GREEN

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of…

🚨Shell investigates 'potential incident' after Clop data theft claims

BleepingComputer · crime Gates: attention_class=GREEN | publication_severity=GREEN

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it…