Home › Blog

NINJA SIGNAL — Edition 000000003

NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)

Threat intel from inside the graph. Published when the signal-to-noise demands it.

Edition 000000003. Three editions in. The receipts are stacking up — let's audit them before anything else, because a forecast you don't grade is just a horoscope.

(NIKO, my editor: A measured, professional opening. I'm concerned.)

(Me: Give it a paragraph, Niko.)

EDITION 002'S FORECAST, GRADED:

① "Another AI/dev-infra CVE on KEV within 10 days — watch anything with 'gateway' in the name." ✅ HIT. Check Point Security Gateway (CVE-2026-50751) is now under active exploitation — the graph logged the velocity spike on June 11. And Sentry (CVE-2026-10520) hit KEV at the 97.57th percentile — your error-monitoring platform, the thing that holds your source maps, stack traces, and half your secrets. Dev infra is the underbelly. Still. Again.

② "The Rundll32 surge precedes a named-malware write-up." ⏳ IN FLIGHT. The spike cooled; no clean named-family attribution yet. Calling it unconfirmed. I'm not going to pretend a miss is a hit — that's the whole point of publishing receipts.

③ "An edge CVE gets chained to active exploitation before Tuesday." ✅ HIT. See ① — Check Point VPN auth-bypass, actively exploited, inside the window.

(NIKO: Two out of three, honestly graded. That's… actually good practice, Scott.)

(Me: Don't sound so surprised.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

⚡ THE SIGNAL — THE PACKAGE REGISTRY IS THE FRONT LINE NOW

Forget the perimeter. The war moved into your package.json and your requirements.txt. This week the graph's velocity engine lit up like a switchboard, and almost every spike was a dependency:

▸ "Nation-State Actors Exploit Notepad++ Supply Chain" — z=13.6. Not a typo. A nation-state, in a text editor's update channel. If they'll burn an operation on Notepad++, nothing in your toolchain is too boring to weaponise.

▸ npm/openclaw — +7 edges, z=14.9 — the single hottest spike in the graph.

▸ pip/open-webui (z=4.7) and pip/PraisonAI (z=5.2) — the AI-tooling thread from Edition 002, still climbing. Open WebUI is what your team bolted onto Ollama. PraisonAI runs agents that execute tools by design.

▸ npm/n8n (z=4.2) — workflow automation with creds to everything.

▸ go/traefik v2 + v3, rust/zebrad, pip/pypdf — Go reverse proxies, a Zcash node, a PDF parser. Breadth across every ecosystem.

▸ P2Pinfect — a Kubernetes worm, mid-compromise.

▸ Cobalt Strike — because of course.

What it means: initial access has been outsourced to your build pipeline. Why phish an employee when you can publish a package their CI installs with full network access and zero EDR? npm, PyPI, Go modules, crates — they're not registries anymore, they're a delivery network with your name on the shipping label.

(NIKO: "Delivery network with your name on the shipping label" is bleak.)

(Me: It's a Tuesday, Niko.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔴 EXPLOIT VELOCITY — WHAT HIT CISA KEV SINCE EDITION 002

▸ CVE-2026-10520 — Sentry · 97.57 pct. The observability platform. It ingests your stack traces, source context, request payloads, and — if your devs were sloppy — tokens and PII. Compromise Sentry and you don't need to break in; you've been handed the blueprints and the spare keys.

▸ CVE-2026-35273 — Oracle PeopleSoft (PeopleTools) · 95.61 pct. ERP/HR. Payroll, PII, org charts. The crown jewels nobody patches because "it's internal."

(NIKO: PeopleSoft is genuinely everywhere and genuinely un-patched.)

(Me: Finally, we agree on something.)

The carry-overs are still hot: Arista EOS (96.52), LiteLLM (98.34), WebLogic (99.59), PAN-OS (98.32). The edge and the AI layer didn't go anywhere.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🎯 DEFENDER QUICKWIN — CATCH THE POSTINSTALL

The supply-chain kill-chain almost always ends the same way: a package install script spawns a downloader. Catch it. This flags a package manager spawning a shell or LOLBin with a network or encoding tell:

DeviceProcessEvents

| where InitiatingProcessFileName in~ ("npm.exe","node.exe","yarn.exe","pnpm.exe",

"pip.exe","pip3.exe","python.exe","python3.exe")

| where FileName in~ ("powershell.exe","cmd.exe","bash.exe","sh.exe","curl.exe",

"certutil.exe","bitsadmin.exe","wscript.exe","cscript.exe")

| where ProcessCommandLine has_any ("http://","https://","-enc","Invoke-",

"DownloadString","FromBase64","IEX","wget","| sh")

| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine

Run it on your build agents first — that's where the lockfiles get resolved and the postinstall scripts run unsupervised. Then run it on every dev laptop.

(NIKO: Three editions, three working detections. I'm updating my opinion of you.)

(Me: Slowly, I hope. I have a reputation.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔮 7-DAY FORECAST (graded next edition, as always)

1. At least one of this week's spiking packages (open-webui / PraisonAI / n8n / openclaw) gets a published IOC report tying it to a real campaign within 10 days. The AI-tooling supply chain is the softest target on the board.

2. A second observability/dev-platform CVE follows Sentry onto KEV inside two weeks — think CI/CD, secrets managers, or feature-flag services. Attackers learned that the tools watching your app are the tools that own your app.

3. The Notepad++ supply-chain compromise expands to at least one more "boring" desktop utility with an auto-updater. Update channels are the new spearphish.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

📊 BY THE NUMBERS — STATE OF THE GRAPH

Nodes ........... 8,193,965 (was 7,896,193)

Edges ........... 50,742,042 (was 48,682,409)

Indicators ...... 446,370

Infrastructure .. 144,349

Vulnerabilities . 47,342

Campaigns ....... 45,385

Threat actors ... 221

Velocity anomalies 306 · TTP convergences 50

Top actors by graph centrality: Fancy Bear (341) · ScarCruft (272) · APT36 (259) · Contagious Interview (203) · Kimsuky (166) · APT28 (137) · APT29 (130) · Lazarus (122) · APT41 (118) · Mustang Panda (109).

Contagious Interview — the DPRK crew that gets hired as your developer — is still top-four, the same week the package registries catch fire. The graph keeps drawing the same line: the threat is aimed at the people and the pipelines that build software.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

WHY THIS EXISTS

Three editions ago I said attribution was breaking. Two ago, that AI tooling was the underbelly. This one: the supply chain is the battlefield and your build agents are unmonitored.

Each one came with a forecast. Each forecast gets graded. Two of three landed this round, and I told you about the one that didn't. That's the deal — radar, not a horoscope. Museum exhibits don't tell you what's coming; this does, then shows you the receipt.

If this helped, follow. If it didn't, follow anyway — Edition 004 I'm mapping the package-registry blast radius across the whole graph, and nobody else has the data to draw it.

Edition 000000003 / 2026-06-15. Data pulled live from ninjasignal.ninja. All numbers reproducible. All receipts published — the hits and the misses.

— Scott

(Niko is quietly impressed and refuses to say so.)

Built on Rapid Threat Modeler | ninja.ing | @scottg

#ThreatIntelligence #CISO #SOC #DFIR #CTI #Cybersecurity #InfoSec #ThreatHunting #CISAKEV #SupplyChain #SoftwareSupplyChain #DevSecOps #AISecurity #BlueTeam

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing