Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
records parsed from the source feeds — before the time window and de-duplication
The digest hands us counts, not the discarded items — so this shows how many and why, not which.
July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.
All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.
But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.
Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.
Seven collection days, no gaps, 77 published items. Over the same period 147 cleared the threshold — more than half were held by the daily cap and reached no page at all. The previous edition closed on who keeps the record. This week shows where the keys are, and what happens when something reaches them that has no end of shift.
The previous edition closed on who keeps the record. This week answers a different question: where the keys are. Not on the endpoints. In the consoles — the tool a provider uses to manage other people’s networks, the remote-access client, the firewall manager, the CI system, the artifact repository, the gateway in front of the models.
The second half of the week says what happens when something reaches them that has no end of shift. Thousands of credentials in six hours. Hundreds of agents across more than 440 instances.
And the week holds both extremes at once: a record Patch Tuesday — and the finding that nearly one in ten internet-facing model gateways still carries the admin key printed in the setup guide. The ceiling of effort and its floor, inside the same seven days. The attacker only needs the floor.
In these seven days 147 items crossed the threshold and 77 were published — 72 chosen by the daily cut and 6 pulled back from items the cap had held; one was dropped as a verbatim repeat of the previous day. The remaining 75 are in the record and appeared on no daily page. The scoring configuration changed twice inside this period — three ran in total — so unlike the previous edition, this week cannot be treated as internally comparable in numbers either. The arc above therefore carries no scores at all and rests only on events. Sunday and Monday are also structurally thin: the collection window reads the PREVIOUS day, so the weekend lull lands on the Monday page rather than the Sunday one — which is why 7 and 13 September carry seven and four items, not twelve.
Seven days, seven pages. The held items stay in the record.
Attention classes are how much attention we gave an item. They are not severity verdicts.
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery…
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in…
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the…
Adolescence co-writer criticises government inaction and calls for laws banning secret use of AI to generate scripts Jack…