TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

13 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
15Fri
15Sat
12Sun
3Mon
12Tue
13Wed
13Thu
IN THE WILD
8/ 13

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.3% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

20 dropped by rule · 17 held by the daily cap · +1 pulled back from the agent-security lane (12 + 1) — items the daily cap held. They ship without an editorial rationale, because held items do not carry one. · config 7E5352F4 — unchanged since 2026-09-09

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
8 4 1
CATEGORIES
exploited7
CVE6
patch-or-mitigation Gates: attention_class=RED | publication_severity=RED6
code-execution4
maximum-severity4
AI/agent3
SOURCES
The Hacker News7
BleepingComputer3
CISA Advisories1
Dark Reading1
SecurityWeek1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News · exploited · CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting…

💥SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker News · CVE · cvss-critical

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended…

🎯CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA Advisories · exploited · CVE

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…

🎯Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News · exploited · msft/identity

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software…

🔑Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News · AI/agent · crime

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys"…

🎯Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News · exploited · CVE

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft…

🎯Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

BleepingComputer · CVE · edge-vendor

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure…

🎯Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News · exploited · CVE

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active…

🎯New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

BleepingComputer · exploited · msft/identity

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named…

🎯Google warns of new Chrome zero-day bug exploited in attacks

BleepingComputer · exploited · urgent-or-active-exploitation

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh…

🚪Ivanti Patches Critical Flaws Across Enterprise Security Products

SecurityWeek · edge-vendor · code-execution

Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches…

🤖Identity-Based AI Attack Threatens Security of Enterprise Data

Dark Reading · AI/agent · identity

"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic…

🤖DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker News · AI/agent