Home › Blog

Ninja Signal — Edition 000000001 / Follow-Up

NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)

The "did our predictions actually happen" report. Receipts.

Six days ago I published three specific, dated, falsifiable forecasts. Most TI vendors quietly forget what they said last week.

This one doesn't.

(NIKO, my editor: I objected to publishing predictions with dates attached.)

(Me: Yes Niko, overruled.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

📊 THE SCOREBOARD

1️⃣ WebLogic mass-scan within 72h ✅ HIT (verified externally)

2️⃣ PAN-OS CVE-2026-0257 in affiliate kit ✅ QUALIFIED HIT (active automated; named attribution pending)

3️⃣ npm/PyPI supply-chain incident <10d ✅ HARD HIT — inside 72 hours

Three for three on signal. Three for three on honesty about what's confirmed and what's not.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

✅ PREDICTION 3 — HARD HIT

The ML logged THREE ecosystem velocity spikes inside the window. All HIGH severity. All in the supply-chain target zone.

▸ npm/nocodb z=15.8 2026-06-05

▸ npm/hono z=8.5 2026-06-04

▸ composer/avideo z=9.9 2026-06-06

For context: z=15.8 means the rate of new edges on that package was ~16 standard deviations above its rolling baseline. The ML didn't flag it. The ML SCREAMED it.

Bonus: the React2Shell AI/LLM-generated malware angle from the original edition? Six days ago it was a footnote infrastructure overlap. Today it's a 20+ entity campaign cluster in the graph.

(NIKO: You're going to be insufferable about this.)

(Me: I haven't even started.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

✅ PREDICTION 1 — HIT (verified externally)

Our own Caddy logs: zero hits. We're not a WebLogic-running target. The prediction was about the wider internet, and the wider internet is on record:

▸ CISA KEV listing (2026-06-01) cited active exploitation, ~1,600 unpatched instances still exposed.

▸ CloudSEK 12-day honeypot study logged 2,902 sessions targeting Oracle WebLogic — significantly higher than any other tracked system.

▸ The Hacker News, SecurityWeek, Cybersecurity News all reported scanner uptick since mid-May 2026, with multiple independent honeypots recording payloads.

The prediction was right. The signal isn't broken; my sightline was. Adding a honeypot/Greynoise ingester for Edition 000000002 so future predictions of this shape grade themselves.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

✅ PREDICTION 2 — QUALIFIED HIT

Confirmed publicly:

▸ Rapid7 MDR first observed exploitation 2026-05-17 — BEFORE this edition published. Two attack waves from Vultr-hosted IPs, then a second wave from Dromatics Systems on May 21.

▸ Palo Alto Unit 42 confirmed active exploitation against PAN-OS GlobalProtect.

▸ Targeting profile: "high-value organizations in financial services and healthcare" — exact Initial Access Broker (IAB) victimology pattern.

▸ Exploit kit is reliable and automated: "iterates through certificate chains and forges cookies for multiple user accounts."

What's not yet confirmed:

▸ A specific named ransomware crew taking custody of this access. Unit 42 notes: "no public attribution linking the exploitation to specific ransomware groups… no post-access behavior or lateral movement identified yet."

My read: technical preconditions all present. Automated weaponised exploit, IAB-shaped targeting, FSI+healthcare focus, cloud-IP scanning infrastructure. The brand name above the dotted line is the remaining gap — and IAB → ransomware-affiliate is usually a 1-4 week handoff, not a 6-day one.

Calling this a qualified hit. The signal happened; the badge hasn't been pinned to a crew yet. If a named affiliate gets attributed in the next week I'll upgrade in Edition 000000002.

(NIKO: You are scoring your own homework.)

(Me: With receipts, Niko. Receipts.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

📈 WHAT ELSE IN 6 DAYS

▸ 225 new community-drift events (38/day)

▸ 8 new velocity anomalies — all HIGH — 5 of 8 in the supply-chain corridor

▸ 50 TTP convergences — unchanged. The "attribution is breaking" thesis didn't gain or lose ground; it's structural, not time-series.

▸ 2 new CISA KEV adds: SolarWinds Serv-U, Mirasvit. Neither in predicted zones.

The headline pattern: the SUPPLY-CHAIN ECOSYSTEM is where the action is right now. If you're not watching your dependency tree, you're not watching the right thing.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔮 NEW 7-DAY FORECAST

1. At least one npm package with >100K weekly downloads will have a malicious version published-then-unpublished in the next 7 days.

2. CVE-2026-0257 (PAN-OS) will be attributed to a named ransomware crew by 2026-06-15. (Upgrades Prediction 2's qualified hit into a strict one — or doesn't.)

3. At least one existing TTP convergence pair (Winter Vivern ↔ VOID MANTICORE, Darkhotel ↔ APT-C-36, etc.) will gain a shared infrastructure overlap event in our graph — turning "they share tradecraft" into "they share kit."

I'll grade these in Edition 000000002.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔗 SOURCES (so you can grade me yourself)

For Prediction 1 (WebLogic):

- Oracle WebLogic CVE-2024-21182 Added to KEV — The Hacker News

- CloudSEK honeypot study — VPNCentral coverage

- CISA Warns of WebLogic Vulnerability — Cybersecurity News

For Prediction 2 (PAN-OS):

- Active Exploitation of PAN-OS CVE-2026-0257 — Palo Alto Unit 42

- Rapid7 Observed Exploitation — Rapid7 ETR blog

- Attackers exploiting Palo Alto defect under the radar — CyberScoop

For Prediction 3 (supply chain) — receipts in our own graph, queryable via the Cypher in 000000001-followup-receipts.json.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🥷 Full receipts in the comments 👇

(NIKO: I objected to making three more predictions.)

(Me: Overruled, Niko.)

(Niko has gone for a lie down.)

— Scott | ninja.ing | @scottg

#ThreatIntelligence #CISO #SOC #DFIR #CTI #SupplyChain #npm #DependencyConfusion #DetectionEngineering #BlueTeam #WebLogic #PaloAlto

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing