TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

12 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
13Wed
13Thu
14Fri
14Sat
4Sun
4Mon
12Tue
IN THE WILD
4/ 12

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.4% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

21 dropped by rule · 14 held by the daily cap · config 90E3557B — unchanged since 2026-09-14

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
3 9
CATEGORIES
AI/agent4
CVE4
cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW3
edge-vendor3
exploited3
msft/identity3
SOURCES
BleepingComputer3
SecurityWeek3
Dark Reading2
CISA Advisories1
CISA KEV1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯CVE-2026-76461 - Cisco Secure Email Gateway: Cisco Secure Email Gateway SQL Injection Vulnerability

CISA KEV · exploited · CVE

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an…

🎯Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

SecurityWeek · exploited · CVE

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

🎯CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories · exploited · CVE

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…

📦Maximum Severity GitLab Flaw Puts Supply Chains at Risk

Dark Reading · CVE · supply-chain

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and…

📰⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

The Hacker News · AI/agent · self-propagating Gates: attention_class=YELLOW | publication_severity=YELLOW

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of…

☁️Hackers target exposed Vite dev servers to steal AWS, Azure secrets

BleepingComputer · crime · msft/identity

A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and…

🪪Microsoft releases emergency Windows updates to fix RDS failures

BleepingComputer · msft/identity · urgent-or-active-exploitation

Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's…

📦CISA: Hackers now exploit max severity GitLab flaw in attacks

BleepingComputer · supply-chain · maximum-severity Gates: attention_class=YELLOW | publication_severity=YELLOW

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity…

🤖Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

SecurityWeek · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work…

🤖Anthropic CEO: Time to Shift From Improving to Controlling AI

Dark Reading · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can…

🤖Microsoft proposes limits on its AI with code of conduct amid safety debate

The Guardian Technology · AI/agent · msft/identity Gates: attention_class=YELLOW | publication_severity=YELLOW

Firm publishes AI guidelines with Microsoft AI CEO saying: ‘AI must be subordinate and always in service of people’…

🪪Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

SecurityWeek · msft/identity · code-execution Gates: attention_class=YELLOW | publication_severity=YELLOW

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.