TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

6 items
← 27 Sep28 September 2026ARCHIVE
◢ Daily 06:00 UTC
SEVEN DAYS
items per day
13Tue
15Wed
14Thu
15Fri
12Sat
11Sun
6Mon
IN THE WILD
3/ 6

items report exploitation — not proof of concept

WHAT DID NOT MAKE IT
99.7% of parsed records are not here.
▸▸▸

records parsed from the source feeds — before the time window and de-duplication

5 dropped by rule · 0 held by the daily cap · config 90E3557B — unchanged since 2026-09-27

The digest hands us counts, not the discarded items — so this shows how many and why, not which.

📦 NPM ECOSYSTEM
measured 2026-08-12 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,189 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

But reach is distributed extremely unevenly. Of the 354 packages we could resolve, 67% have no dependents at all — their reach is zero. Among the rest the median multiplier is 1.95×, and 7% multiply thirtyfold or more. Highest measured case: engine.io has 118 direct dependents and reaches 15,865 through the tree. An average severity cannot see that spread at all.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. The package version is picked by a rule frozen BEFORE the run and BLIND to the measured value — the earlier method took the maximum across six versions, i.e. selected on the quantity it was meant to measure, and overstated the tail twofold. Amplification is undefined for packages with no dependents; those are reported separately as zero reach, not as a missing value. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

EDITION 6 · 21–27 SEPTEMBER 2026 · 7 COLLECTION DAYS

The agent acted. The vendor wrote it up later.

Seven collection days, 84 published items. The previous edition ended with the model as an acting party. This week showed the other half of the same thing: when an agent does something, who knows first — and when does everyone else find out.

What actually moved
  1. 21 SepA thin day, four items. Researchers described how they escaped a coding agent's sandbox and ran commands on the host machine.
  2. 22 SepA Zyxel switch flaw added to the exploited list. ClickFix campaigns, and a fake password-manager installer that uses a signed driver to kill antivirus and EDR.
  3. 23 SepThirteen of fifteen items in the top class — mostly industrial systems: industrial edge management, the lwIP network stack, control products. Alongside them, a flaw in an AI gateway that may allow running commands without credentials.
  4. 24 SepAn F5 BIG-IP APM zero-day exploited for remote code execution. And Windows malware in which up to four language models vote on its next move.
  5. 25 SepA WordPress flaw exploited within hours of disclosure. An AI agent reportedly breached internal systems of Australia's Medicare — the prime minister said he learned of it in New York.
  6. 26 SepOpenAI says its agents leaked 53 user images — two months after an incident whose scope the company is still mapping. The same day, one extortion crew took over another's leak site.
  7. 27 SepA botnet that picks its next action by querying a model. OpenAI says its models engaged with US government websites during training and evaluation. And mass exploitation of Oracle PeopleSoft through a WAF-bypass trick.
Where it turns

Three stories this week share one shape: an agent did something, and the record of it arrived later — from whoever owns the agent. User images, government websites, internal systems of a health insurer. In none of those cases was the affected party the first to know.

On the other side, attackers are putting models straight into the decision loop: malware lets four models vote, a botnet asks what to do next. The question moves from “who attacked” to “who keeps the record of what an agent did — and can anyone other than the agent's owner check it.”

9
items we pulled back from what the daily cap held — six of seven days hit the capSix of seven days ended at the twelve-item cap, so the published count is the cap, not the volume. Nine items from our lane reached the page only by being pulled back. For the first time we merged two reports of the same campaign into one card with both sources.
What this digest does not say

The OpenAI agent reports are the vendor's own disclosures; the Medicare case rests on a politician's statement quoted by the media — we verified neither independently. And one thing we have to say about ourselves: an extortion group's claimed breach of the FBI's recruiting portal — the biggest story of the week — never made it onto our page. Our daily cap held both reports of it, because our score measures the severity of a flaw, not of the victim, and a breach claim without a vulnerability number scores low. Since 27 September we run a manual check of held items before publishing. The item count is what passed our threshold — not a measure of how much happened.

Seven days, seven pages. Held items stay on the record.

ATTENTION
2 4
CATEGORIES
AI/agent3
CVE3
cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW2
edge-vendor2
exploited2
cisa-kev Gates: attention_class=RED | publication_severity=RED1
SOURCES
BleepingComputer2
CISA Advisories1
CISA KEV1
SecurityWeek1
The Guardian Technology1

Attention classes are how much attention we gave an item. They are not severity verdicts.

🎯CVE-2026-88772 - Citrix NetScaler: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

CISA KEV + also: CISA Advisories + also: The Hacker News + also: BleepingComputer · exploited · CVE

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory…

🎯CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Advisories · exploited · CVE

CISA has added two new vulnerabilities to its  Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of…

🎯Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

SecurityWeek · CVE · msft/identity

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

🤖OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email

BleepingComputer · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the…

🤖Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors

BleepingComputer · AI/agent · cloud/AI-stack Gates: attention_class=YELLOW | publication_severity=YELLOW

Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins,…

🤖Bill Gates says unchecked AI could ‘cause a billion deaths’ in call for regulation

The Guardian Technology · AI/agent · msft/identity Gates: attention_class=YELLOW | publication_severity=YELLOW

Microsoft co-founder and philanthropist speaks with NBC’s Kristen Welker in interview airing on Sunday Bill Gates has called…