TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

15 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
12Sat
2Sun
11Mon
13Tue
15Wed
15Thu
15Fri
IN THE WILD
1/ 15

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.2% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

14 dropped by rule · 29 held by the daily cap · +3 pulled back from the agent-security lane (12 + 3) — items the daily cap held. They ship without an editorial rationale, because held items do not carry one. · config 8302303C — unchanged since 2026-09-03

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
12 3
CATEGORIES
CVE11
patch-or-mitigation Gates: attention_class=RED | publication_severity=RED10
crime9
critical-infra-disruption9
critical-infra/OT9
AI/agent4
SOURCES
CISA Advisories9
The Hacker News3
Dark Reading2
SecurityWeek1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🚪IXON VPN Client

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on…

📦OPCFoundation OPC UA LocalDiscoveryServer (LDS)

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege…

📦Tycon Systems TPDIN-Monitor-WEB3

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a…

🔑Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News · AI/agent · crime

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for…

🩹Rockwell Automation ControlFLASH

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or…

🎯CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The Hacker News · exploited · CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known…

🩹Tycon Systems TPDIN-Monitor-WEB2 (Update A)

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive…

🩹Inductive Automation Ignition

CISA Advisories · CVE · crime

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects.

🚪Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · CVE · edge-vendor

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could…

🩹Rockwell Automation 1756-ENBT Module

CISA Advisories · CVE · critical-infra/OT

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to…

🩹Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

CISA Advisories · CVE · critical-infra/OT

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and…

🩹Rockwell Automation ArmorStart LT

CISA Advisories · CVE · critical-infra/OT

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow…

📦AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

SecurityWeek · AI/agent · supply-chain

💧What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

Dark Reading · AI/agent · crime

🤖AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

Dark Reading · AI/agent · crime