NINJA SIGNAL — Edition 000000003
NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)
Threat intel from inside the graph. Published when the signal-to-noise demands it.
Edition 000000003. Three editions in. The receipts are stacking up — let's audit them before anything else, because a forecast you don't grade is just a horoscope.
(NIKO, my editor: A measured, professional opening. I'm concerned.)
(Me: Give it a paragraph, Niko.)
EDITION 002'S FORECAST, GRADED:
① "Another AI/dev-infra CVE on KEV within 10 days — watch anything with 'gateway' in the name." ✅ HIT. Check Point Security Gateway (CVE-2026-50751) is now under active exploitation — the graph logged the velocity spike on June 11. And Sentry (CVE-2026-10520) hit KEV at the 97.57th percentile — your error-monitoring platform, the thing that holds your source maps, stack traces, and half your secrets. Dev infra is the underbelly. Still. Again.
② "The Rundll32 surge precedes a named-malware write-up." ⏳ IN FLIGHT. The spike cooled; no clean named-family attribution yet. Calling it unconfirmed. I'm not going to pretend a miss is a hit — that's the whole point of publishing receipts.
③ "An edge CVE gets chained to active exploitation before Tuesday." ✅ HIT. See ① — Check Point VPN auth-bypass, actively exploited, inside the window.
(NIKO: Two out of three, honestly graded. That's… actually good practice, Scott.)
(Me: Don't sound so surprised.)
━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚡ THE SIGNAL — THE PACKAGE REGISTRY IS THE FRONT LINE NOW
Forget the perimeter. The war moved into your package.json and your requirements.txt. This week the graph's velocity engine lit up like a switchboard, and almost every spike was a dependency:
▸ "Nation-State Actors Exploit Notepad++ Supply Chain" — z=13.6. Not a typo. A nation-state, in a text editor's update channel. If they'll burn an operation on Notepad++, nothing in your toolchain is too boring to weaponise.
▸ npm/openclaw — +7 edges, z=14.9 — the single hottest spike in the graph.
▸ pip/open-webui (z=4.7) and pip/PraisonAI (z=5.2) — the AI-tooling thread from Edition 002, still climbing. Open WebUI is what your team bolted onto Ollama. PraisonAI runs agents that execute tools by design.
▸ npm/n8n (z=4.2) — workflow automation with creds to everything.
▸ go/traefik v2 + v3, rust/zebrad, pip/pypdf — Go reverse proxies, a Zcash node, a PDF parser. Breadth across every ecosystem.
▸ P2Pinfect — a Kubernetes worm, mid-compromise.
▸ Cobalt Strike — because of course.
What it means: initial access has been outsourced to your build pipeline. Why phish an employee when you can publish a package their CI installs with full network access and zero EDR? npm, PyPI, Go modules, crates — they're not registries anymore, they're a delivery network with your name on the shipping label.
(NIKO: "Delivery network with your name on the shipping label" is bleak.)
(Me: It's a Tuesday, Niko.)
━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔴 EXPLOIT VELOCITY — WHAT HIT CISA KEV SINCE EDITION 002
▸ CVE-2026-10520 — Sentry · 97.57 pct. The observability platform. It ingests your stack traces, source context, request payloads, and — if your devs were sloppy — tokens and PII. Compromise Sentry and you don't need to break in; you've been handed the blueprints and the spare keys.
▸ CVE-2026-35273 — Oracle PeopleSoft (PeopleTools) · 95.61 pct. ERP/HR. Payroll, PII, org charts. The crown jewels nobody patches because "it's internal."
(NIKO: PeopleSoft is genuinely everywhere and genuinely un-patched.)
(Me: Finally, we agree on something.)
The carry-overs are still hot: Arista EOS (96.52), LiteLLM (98.34), WebLogic (99.59), PAN-OS (98.32). The edge and the AI layer didn't go anywhere.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎯 DEFENDER QUICKWIN — CATCH THE POSTINSTALL
The supply-chain kill-chain almost always ends the same way: a package install script spawns a downloader. Catch it. This flags a package manager spawning a shell or LOLBin with a network or encoding tell:
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("npm.exe","node.exe","yarn.exe","pnpm.exe",
"pip.exe","pip3.exe","python.exe","python3.exe")
| where FileName in~ ("powershell.exe","cmd.exe","bash.exe","sh.exe","curl.exe",
"certutil.exe","bitsadmin.exe","wscript.exe","cscript.exe")
| where ProcessCommandLine has_any ("http://","https://","-enc","Invoke-",
"DownloadString","FromBase64","IEX","wget","| sh")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine
Run it on your build agents first — that's where the lockfiles get resolved and the postinstall scripts run unsupervised. Then run it on every dev laptop.
(NIKO: Three editions, three working detections. I'm updating my opinion of you.)
(Me: Slowly, I hope. I have a reputation.)
━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔮 7-DAY FORECAST (graded next edition, as always)
1. At least one of this week's spiking packages (open-webui / PraisonAI / n8n / openclaw) gets a published IOC report tying it to a real campaign within 10 days. The AI-tooling supply chain is the softest target on the board.
2. A second observability/dev-platform CVE follows Sentry onto KEV inside two weeks — think CI/CD, secrets managers, or feature-flag services. Attackers learned that the tools watching your app are the tools that own your app.
3. The Notepad++ supply-chain compromise expands to at least one more "boring" desktop utility with an auto-updater. Update channels are the new spearphish.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
📊 BY THE NUMBERS — STATE OF THE GRAPH
Nodes ........... 8,193,965 (was 7,896,193)
Edges ........... 50,742,042 (was 48,682,409)
Indicators ...... 446,370
Infrastructure .. 144,349
Vulnerabilities . 47,342
Campaigns ....... 45,385
Threat actors ... 221
Velocity anomalies 306 · TTP convergences 50
Top actors by graph centrality: Fancy Bear (341) · ScarCruft (272) · APT36 (259) · Contagious Interview (203) · Kimsuky (166) · APT28 (137) · APT29 (130) · Lazarus (122) · APT41 (118) · Mustang Panda (109).
Contagious Interview — the DPRK crew that gets hired as your developer — is still top-four, the same week the package registries catch fire. The graph keeps drawing the same line: the threat is aimed at the people and the pipelines that build software.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
WHY THIS EXISTS
Three editions ago I said attribution was breaking. Two ago, that AI tooling was the underbelly. This one: the supply chain is the battlefield and your build agents are unmonitored.
Each one came with a forecast. Each forecast gets graded. Two of three landed this round, and I told you about the one that didn't. That's the deal — radar, not a horoscope. Museum exhibits don't tell you what's coming; this does, then shows you the receipt.
If this helped, follow. If it didn't, follow anyway — Edition 004 I'm mapping the package-registry blast radius across the whole graph, and nobody else has the data to draw it.
Edition 000000003 / 2026-06-15. Data pulled live from ninjasignal.ninja. All numbers reproducible. All receipts published — the hits and the misses.
— Scott
(Niko is quietly impressed and refuses to say so.)
Built on Rapid Threat Modeler | ninja.ing | @scottg
#ThreatIntelligence #CISO #SOC #DFIR #CTI #Cybersecurity #InfoSec #ThreatHunting #CISAKEV #SupplyChain #SoftwareSupplyChain #DevSecOps #AISecurity #BlueTeam
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·