Cyber Signal
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.
items report exploitation — not proof of concept
records parsed from the source feeds — before the time window and de-duplication
The digest hands us counts, not the discarded items — so this shows how many and why, not which.
July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.
All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.
But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.
Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.
Seven collection days, 84 published items. The previous edition ended with the model as an acting party. This week showed the other half of the same thing: when an agent does something, who knows first — and when does everyone else find out.
Three stories this week share one shape: an agent did something, and the record of it arrived later — from whoever owns the agent. User images, government websites, internal systems of a health insurer. In none of those cases was the affected party the first to know.
On the other side, attackers are putting models straight into the decision loop: malware lets four models vote, a botnet asks what to do next. The question moves from “who attacked” to “who keeps the record of what an agent did — and can anyone other than the agent's owner check it.”
The OpenAI agent reports are the vendor's own disclosures; the Medicare case rests on a politician's statement quoted by the media — we verified neither independently. And one thing we have to say about ourselves: an extortion group's claimed breach of the FBI's recruiting portal — the biggest story of the week — never made it onto our page. Our daily cap held both reports of it, because our score measures the severity of a flaw, not of the victim, and a breach claim without a vulnerability number scores low. Since 27 September we run a manual check of held items before publishing. The item count is what passed our threshold — not a measure of how much happened.
Seven days, seven pages. Held items stay on the record.
Attention classes are how much attention we gave an item. They are not severity verdicts.
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of…
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the…
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins,…
Microsoft co-founder and philanthropist speaks with NBC’s Kristen Welker in interview airing on Sunday Bill Gates has called…