TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

14 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
14Fri
15Sat
9Sun
4Mon
13Tue
15Wed
14Thu
IN THE WILD
6/ 14

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.3% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

14 dropped by rule · 21 held by the daily cap · +2 pulled back from the agent-security lane (12 + 2) — items the daily cap held. They ship without an editorial rationale, because held items do not carry one. · config 90E3557B — unchanged since 2026-09-23

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
3 9 2
CATEGORIES
exploited6
AI/agent5
CVE4
crime4
code-execution3
patch-or-mitigation Gates: attention_class=RED | publication_severity=YELLOW | classification_divergence.kind=threshold_policy_split3
SOURCES
The Hacker News5
BleepingComputer4
SecurityWeek3
CISA Advisories1
Dark Reading1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker News · exploited · CVE

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system…

🚪This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

The Hacker News · AI/agent · crime

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's…

📦Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

CISA Advisories · supply-chain · critical-infra/OT

Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter…

🔑Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News · crime · supply-chain

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index…

🎯Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · exploited · CVE

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows…

🎯Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

BleepingComputer · exploited · CVE

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code…

📦Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

The Hacker News · CVE · supply-chain

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host,…

🎣AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

SecurityWeek · AI/agent · crime

The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and…

🎯Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

SecurityWeek · exploited · code-execution

Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.

🎯Arista patches actively exploited VeloCloud Orchestrator zero-day

BleepingComputer · exploited · urgent-or-active-exploitation

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud…

🎯F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

BleepingComputer · exploited · code-execution

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code…

🎣Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

Dark Reading · AI/agent · crime

Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data…

🤖Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

BleepingComputer · AI/agent

🤖Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

SecurityWeek · AI/agent