Home › Blog

NINJA SIGNAL — Edition 000000003 Receipts first.

NINJA SIGNAL — Edition 000000003

Receipts first. Two editions ago I called LLM tooling the soft underbelly; last edition I forecast three things and put money on them. Grading:

① "Another AI/dev-infra CVE on KEV — watch anything with 'gateway' in the name." ✅ HIT — Check Point Security Gateway under active exploitation + Sentry on KEV at 97.57 pct.

② "Rundll32 surge precedes a named-malware write-up." ⏳ IN FLIGHT — unconfirmed. Not pretending a miss is a hit.

③ "An edge CVE chained to active exploitation before Tuesday." ✅ HIT — Check Point VPN auth-bypass, in the window.

Two of three. I'll tell you about the one that didn't land — that's the whole point.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

⚡ THE PACKAGE REGISTRY IS THE FRONT LINE NOW

The war moved into your package.json and your requirements.txt. This week's velocity spikes were almost all dependencies:

▸ "Nation-State Actors Exploit Notepad++ Supply Chain" — z=13.6. A nation-state. In a text editor's update channel.
▸ npm/openclaw — z=14.9, the hottest spike in the graph.
▸ pip/open-webui + pip/PraisonAI — the AI-tooling thread, still climbing. Open WebUI bolts onto Ollama; PraisonAI runs agents that execute tools by design.
▸ npm/n8n, go/traefik v2+v3, rust/zebrad, pip/pypdf — breadth across every ecosystem.
▸ P2Pinfect (Kubernetes worm) + Cobalt Strike, because of course.

Initial access has been outsourced to your build pipeline. Why phish an employee when you can publish a package their CI installs with full network access and zero EDR?

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔴 KEV THIS WEEK — OBSERVABILITY + ERP

▸ CVE-2026-10520 Sentry — 97.57 pct. Your error-monitoring platform holds stack traces, source context, request payloads — and the secrets your devs forgot to scrub. Own Sentry, own the blueprints.
▸ CVE-2026-35273 Oracle PeopleSoft — 95.61 pct. Payroll, PII, org charts. Crown jewels nobody patches because "it's internal."

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🎯 DEFENDER QUICKWIN — catch the postinstall

The supply-chain kill-chain ends the same way: a package install script spawns a downloader. Flag package managers (npm/yarn/pnpm/pip/node/python) spawning powershell/cmd/bash/curl/certutil with a network or encoding tell (http, -enc, DownloadString, FromBase64, IEX, | sh). Run it on your build agents FIRST — that's where postinstall runs unsupervised. (Full KQL in the comments.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔮 7-DAY FORECAST (graded next edition)

1. One of this week's spiking packages (open-webui / PraisonAI / n8n / openclaw) gets a published IOC report tying it to a real campaign within 10 days.
2. A second observability/dev-platform CVE follows Sentry onto KEV in two weeks (CI/CD, secrets managers, feature flags).
3. The Notepad++ supply-chain compromise expands to another "boring" desktop utility with an auto-updater.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

Full edition + KQL + receipts (hits AND misses) in the comments 👇

— Scott | ninja.ing | @scottg

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing