TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

12 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
3Sun
2Mon
12Tue
12Wed
12Thu
12Fri
12Sat
IN THE WILD
3/ 12

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.4% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

11 dropped by rule · 17 held by the daily cap · config 8302303C — unchanged since 2026-08-28

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
2 10
CATEGORIES
AI/agent5
exploited4
patch-or-mitigation Gates: attention_class=RED | publication_severity=YELLOW | classification_divergence.kind=threshold_policy_split4
CVE3
urgent-or-active-exploitation3
cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW2
SOURCES
The Hacker News7
SecurityWeek3
BleepingComputer1
The Guardian Technology1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The Hacker News · exploited · CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting…

🤖Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News · AI/agent · cvss-critical

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on…

🎯China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

The Hacker News · exploited · CVE

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong…

🩹Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News · code-execution · unauthenticated

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible…

🎯PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

The Hacker News · exploited · urgent-or-active-exploitation

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its…

🎯PaperCut Releases Emergency Patch for Exploited Zero-Day

SecurityWeek · exploited · urgent-or-active-exploitation

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

🤖ServiceNow warns of three max severity security vulnerabilities

BleepingComputer · AI/agent · maximum-severity

ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in…

📦Pentagon’s blacklisting of Anthropic was unlawful, US judge rules

The Guardian Technology · AI/agent · supply-chain

Anthropic ​argued designation as ‘supply-chain risk’ could cost billions ‌in lost business ‌and reputational harm A US judge…

🩹Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker News · CVE · code-execution

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and…

🚪Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

SecurityWeek · AI/agent · edge-vendor Gates: attention_class=YELLOW | publication_severity=YELLOW

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and…

🤖Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge

SecurityWeek · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more…

₿19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News · crime · msft/identity Gates: attention_class=YELLOW | publication_severity=YELLOW

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were…