TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

4 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
12Tue
13Wed
13Thu
14Fri
14Sat
4Sun
4Mon
IN THE WILD
1/ 4

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.8% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

8 dropped by rule · 0 held by the daily cap · config 90E3557B — unchanged since 2026-09-13

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

EDITION 4 · 7–13 SEPTEMBER 2026 · 7 COLLECTION DAYS

The target was not the endpoints. It was the consoles.

Seven collection days, no gaps, 77 published items. Over the same period 147 cleared the threshold — more than half were held by the daily cap and reached no page at all. The previous edition closed on who keeps the record. This week shows where the keys are, and what happens when something reaches them that has no end of shift.

What actually moved
  1. 7 SepN-able N-central was patched for a maximum-severity flaw amid ongoing attacks. It is the tool providers use to manage other people’s networks.
  2. 8 SepThe same product received its fourth hotfix in five weeks. The same day: rogue ScreenConnect clients were reported spreading a four-stage chain to newly connected hosts, and an Adobe Commerce zero-day was backdooring online stores.
  3. 9 SepSeptember Patch Tuesday: 966 flaws, two exploited. Alongside it, a number with nothing to do with patching — autonomous agents were reported compromising thousands of credentials in under six hours.
  4. 10 SepSAP patched a CVSS 10.0 kernel flaw exploitable without authentication. Cisco confirmed exploitation of a flaw in its firewall management product. In the same cut: infostealer logs were said to expose replayable AI service tokens that bypass multi-factor authentication.
  5. 11 SepA federal patch deadline for Cisco, Citrix and Fortinet. NetScaler under exploitation. And two things side by side: a PaperCut attacker was reported using hundreds of agents to reach more than 440 instances — while nearly one in ten internet-facing LiteLLM gateways accepted the example admin key from the vendor’s own setup guide.
  6. 12 SepConnectWise ScreenConnect: improper privilege management and missing authorisation. GitLab at CVSS 10. Cisco FMC flaws reportedly used to steal credentials and deploy Qilin ransomware.
  7. 13 SepCISA added Artifactory, ScreenConnect and RouterOS to its exploited catalogue at once. OpenAI agents were linked, in a new report, to a RubyGems campaign that gained RCE on RubyDoc servers.
The shift

The previous edition closed on who keeps the record. This week answers a different question: where the keys are. Not on the endpoints. In the consoles — the tool a provider uses to manage other people’s networks, the remote-access client, the firewall manager, the CI system, the artifact repository, the gateway in front of the models.

The second half of the week says what happens when something reaches them that has no end of shift. Thousands of credentials in six hours. Hundreds of agents across more than 440 instances.

And the week holds both extremes at once: a record Patch Tuesday — and the finding that nearly one in ten internet-facing model gateways still carries the admin key printed in the setup guide. The ceiling of effort and its floor, inside the same seven days. The attacker only needs the floor.

75
items cleared the threshold and were held by the cap — more than half of everything that qualifiedFive of the seven days hit the publication cap of twelve, so the published count is a ceiling, not a volume. Six of those held items we pulled back ourselves through a reserved agent-security lane; the rest stayed in the record. The figure comes from our own record, not from an independent taxonomy.
What does not follow

In these seven days 147 items crossed the threshold and 77 were published — 72 chosen by the daily cut and 6 pulled back from items the cap had held; one was dropped as a verbatim repeat of the previous day. The remaining 75 are in the record and appeared on no daily page. The scoring configuration changed twice inside this period — three ran in total — so unlike the previous edition, this week cannot be treated as internally comparable in numbers either. The arc above therefore carries no scores at all and rests only on events. Sunday and Monday are also structurally thin: the collection window reads the PREVIOUS day, so the weekend lull lands on the Monday page rather than the Sunday one — which is why 7 and 13 September carry seven and four items, not twelve.

Seven days, seven pages. The held items stay in the record.

ATTENTION
4
CATEGORIES
AI/agent2
msft/identity2
CVE1
cloud/AI-stack Gates: attention_class=RED | publication_severity=YELLOW | classification_divergence.kind=threshold_policy_split1
cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW1
crime1
SOURCES
BleepingComputer1
SecurityWeek1
The Guardian Technology1
The Hacker News1

Attention classes are how much attention we gave an item. They are not severity verdicts.