Ninja Signal — Edition 000000001 / Follow-Up
NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)
The "did our predictions actually happen" report. Receipts.
Six days ago I published three specific, dated, falsifiable forecasts. Most TI vendors quietly forget what they said last week.
This one doesn't.
(NIKO, my editor: I objected to publishing predictions with dates attached.)
(Me: Yes Niko, overruled.)
━━━━━━━━━━━━━━━━━━━━━━━━━━━
📊 THE SCOREBOARD
1️⃣ WebLogic mass-scan within 72h ✅ HIT (verified externally)
2️⃣ PAN-OS CVE-2026-0257 in affiliate kit ✅ QUALIFIED HIT (active automated; named attribution pending)
3️⃣ npm/PyPI supply-chain incident <10d ✅ HARD HIT — inside 72 hours
Three for three on signal. Three for three on honesty about what's confirmed and what's not.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ PREDICTION 3 — HARD HIT
The ML logged THREE ecosystem velocity spikes inside the window. All HIGH severity. All in the supply-chain target zone.
▸ npm/nocodb z=15.8 2026-06-05
▸ npm/hono z=8.5 2026-06-04
▸ composer/avideo z=9.9 2026-06-06
For context: z=15.8 means the rate of new edges on that package was ~16 standard deviations above its rolling baseline. The ML didn't flag it. The ML SCREAMED it.
Bonus: the React2Shell AI/LLM-generated malware angle from the original edition? Six days ago it was a footnote infrastructure overlap. Today it's a 20+ entity campaign cluster in the graph.
(NIKO: You're going to be insufferable about this.)
(Me: I haven't even started.)
━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ PREDICTION 1 — HIT (verified externally)
Our own Caddy logs: zero hits. We're not a WebLogic-running target. The prediction was about the wider internet, and the wider internet is on record:
▸ CISA KEV listing (2026-06-01) cited active exploitation, ~1,600 unpatched instances still exposed.
▸ CloudSEK 12-day honeypot study logged 2,902 sessions targeting Oracle WebLogic — significantly higher than any other tracked system.
▸ The Hacker News, SecurityWeek, Cybersecurity News all reported scanner uptick since mid-May 2026, with multiple independent honeypots recording payloads.
The prediction was right. The signal isn't broken; my sightline was. Adding a honeypot/Greynoise ingester for Edition 000000002 so future predictions of this shape grade themselves.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ PREDICTION 2 — QUALIFIED HIT
Confirmed publicly:
▸ Rapid7 MDR first observed exploitation 2026-05-17 — BEFORE this edition published. Two attack waves from Vultr-hosted IPs, then a second wave from Dromatics Systems on May 21.
▸ Palo Alto Unit 42 confirmed active exploitation against PAN-OS GlobalProtect.
▸ Targeting profile: "high-value organizations in financial services and healthcare" — exact Initial Access Broker (IAB) victimology pattern.
▸ Exploit kit is reliable and automated: "iterates through certificate chains and forges cookies for multiple user accounts."
What's not yet confirmed:
▸ A specific named ransomware crew taking custody of this access. Unit 42 notes: "no public attribution linking the exploitation to specific ransomware groups… no post-access behavior or lateral movement identified yet."
My read: technical preconditions all present. Automated weaponised exploit, IAB-shaped targeting, FSI+healthcare focus, cloud-IP scanning infrastructure. The brand name above the dotted line is the remaining gap — and IAB → ransomware-affiliate is usually a 1-4 week handoff, not a 6-day one.
Calling this a qualified hit. The signal happened; the badge hasn't been pinned to a crew yet. If a named affiliate gets attributed in the next week I'll upgrade in Edition 000000002.
(NIKO: You are scoring your own homework.)
(Me: With receipts, Niko. Receipts.)
━━━━━━━━━━━━━━━━━━━━━━━━━━━
📈 WHAT ELSE IN 6 DAYS
▸ 225 new community-drift events (38/day)
▸ 8 new velocity anomalies — all HIGH — 5 of 8 in the supply-chain corridor
▸ 50 TTP convergences — unchanged. The "attribution is breaking" thesis didn't gain or lose ground; it's structural, not time-series.
▸ 2 new CISA KEV adds: SolarWinds Serv-U, Mirasvit. Neither in predicted zones.
The headline pattern: the SUPPLY-CHAIN ECOSYSTEM is where the action is right now. If you're not watching your dependency tree, you're not watching the right thing.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔮 NEW 7-DAY FORECAST
1. At least one npm package with >100K weekly downloads will have a malicious version published-then-unpublished in the next 7 days.
2. CVE-2026-0257 (PAN-OS) will be attributed to a named ransomware crew by 2026-06-15. (Upgrades Prediction 2's qualified hit into a strict one — or doesn't.)
3. At least one existing TTP convergence pair (Winter Vivern ↔ VOID MANTICORE, Darkhotel ↔ APT-C-36, etc.) will gain a shared infrastructure overlap event in our graph — turning "they share tradecraft" into "they share kit."
I'll grade these in Edition 000000002.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔗 SOURCES (so you can grade me yourself)
For Prediction 1 (WebLogic):
- Oracle WebLogic CVE-2024-21182 Added to KEV — The Hacker News
- CloudSEK honeypot study — VPNCentral coverage
- CISA Warns of WebLogic Vulnerability — Cybersecurity News
For Prediction 2 (PAN-OS):
- Active Exploitation of PAN-OS CVE-2026-0257 — Palo Alto Unit 42
- Rapid7 Observed Exploitation — Rapid7 ETR blog
- Attackers exploiting Palo Alto defect under the radar — CyberScoop
For Prediction 3 (supply chain) — receipts in our own graph, queryable via the Cypher in 000000001-followup-receipts.json.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
🥷 Full receipts in the comments 👇
(NIKO: I objected to making three more predictions.)
(Me: Overruled, Niko.)
(Niko has gone for a lie down.)
— Scott | ninja.ing | @scottg
#ThreatIntelligence #CISO #SOC #DFIR #CTI #SupplyChain #npm #DependencyConfusion #DetectionEngineering #BlueTeam #WebLogic #PaloAlto
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·