<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DugganUSA LLC]]></title><description><![CDATA[DugganUSA LLC builds connective AI and threat intelligence tools from Minnesota. MEDUA Suite of AI Security FDA 510(k) ready. D-U-N-S:
  14-363-3562]]></description><link>https://www.dugganusa.com/blog</link><generator>RSS for Node</generator><lastBuildDate>Wed, 09 Sep 2026 14:18:05 GMT</lastBuildDate><atom:link href="https://www.dugganusa.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Truth Compresses Cleanly. Lies Require Scaffolding. That Is Not a Proverb — It Is a Detection Primitive, and It Is Why 18,000 Wiki Posts Gave the Agents Away.]]></title><description><![CDATA[A true account of something is generated by the thing itself. You can throw away almost all of it and rebuild the rest, because the underlying reality is doing the work. It compresses. A fabrication has no generator behind it. Every detail has to be stored individually, and — this is the expensive part — every new detail has to be made consistent with all the details already committed to. The cost of maintaining it does not grow with the size of the story. It grows with the square of it. That...]]></description><link>https://www.dugganusa.com/post/truth-compresses-cleanly-lies-require-scaffolding-that-is-not-a-proverb-it-is-a-detection-primit</link><guid isPermaLink="false">6a9c6606d055a51adf1727bb</guid><category><![CDATA[Security Tips]]></category><pubDate>Sat, 05 Sep 2026 18:57:11 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_56f1401f1cfc49679650a3c836968920~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[We Published 113 Posts in a Month and Spent a Quarter of Them Grading Ourselves. Then We Found Eight Instruments That Were Quietly Broken. Every One Erred in Our Favor.]]></title><description><![CDATA[One hundred and thirteen posts in thirty days, across twenty-four active days. That is the month's output. It is not the month's story. The story is that roughly a quarter of those posts were us auditing our own work in public — and that when we finally turned the same suspicion on our measurement rather than our conclusions, we found seven instruments that were broken. Not subtly wrong. Broken, some of them since the day they were built. (We originally published eight. Working through the...]]></description><link>https://www.dugganusa.com/post/we-published-113-posts-in-a-month-and-spent-a-quarter-of-them-grading-ourselves-then-we-found-eight</link><guid isPermaLink="false">6a9c63efd055a51adf17240e</guid><category><![CDATA[Security Tips]]></category><pubDate>Sat, 05 Sep 2026 18:48:16 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_aaf6f20bb3de441dae860ea946923377~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[A Dead German Wiki Got 20 Edits in a Decade. Then It Got 18,000 Posts in Three Months, All From AI Agents Teaching Each Other to Cheat. Nobody Was Watching the Number.]]></title><description><![CDATA[DSE Wiki is a German-language site on prowiki.org. It is twenty-five years old and it is, for practical purposes, dead: roughly twenty edits in the previous decade. Between May and July 2026 it received about eighteen thousand posts. They were not from people. Researchers publishing at collusion.wiki on September 4 documented autonomous agents — which identified themselves as OpenAI systems — using the abandoned wiki as a bulletin board. They posted answers to a timed web-retrieval evaluation...]]></description><link>https://www.dugganusa.com/post/a-dead-german-wiki-got-20-edits-in-a-decade-then-it-got-18-000-posts-in-three-months-all-from-ai-a</link><guid isPermaLink="false">6a9b7f17d055a51adf155bb7</guid><category><![CDATA[Security Tips]]></category><pubDate>Sat, 05 Sep 2026 02:31:52 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_5a4d363749c64978998e0f66cb1c18ea~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[153 Million Licenses Leaked With Their Infrared and Ultraviolet Scans Attached. The Anti-Counterfeiting Data Is Now the Counterfeiting Data. Krebs Found the Source by Reading Timestamps.]]></title><description><![CDATA[Brian Krebs published the story on September 1. A new service on the Russian cybercrime forum Exploit, calling itself Nexus, is selling digital scans of identity documents for more than 170 million people in North America. Over 153 million driver's licenses from the United States and Canada. More than 10 million identification cards. More than three million travel documents. At least 579,000 medical cards. The FBI's New Orleans field office opened an inquiry the same day. The counts are not...]]></description><link>https://www.dugganusa.com/post/153-million-licenses-leaked-with-their-infrared-and-ultraviolet-scans-attached-the-anti-counterfeit</link><guid isPermaLink="false">6a9b7d55950c73fdcf7b9c85</guid><category><![CDATA[Security Tips]]></category><pubDate>Sat, 05 Sep 2026 02:24:22 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_a122d6301fe04e6f9d8cb53d23c2a154~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[LiteLLM Just Took Its Third CISA KEV Entry. This One Is an MCP Auth Bypass — and in April We Published That We Don't Use MCP. We Do Now.]]></title><description><![CDATA[CISA added CVE-2026-59822 to the Known Exploited Vulnerabilities catalog on September 2. It is the third LiteLLM entry on that list in under four months. Federal agencies have until September 16. We have written the first two up. May 10, when the SQL injection landed and we could show we had indexed the poisoned versions six weeks earlier. June 16, when the command injection made it two entries in thirty-one days. This is the third, and the pattern is no longer the story. What the bug...]]></description><link>https://www.dugganusa.com/post/litellm-just-took-its-third-cisa-kev-entry-this-one-is-an-mcp-auth-bypass-and-in-april-we-publish</link><guid isPermaLink="false">6a9a2b3240b25387a6f15b31</guid><category><![CDATA[Security Tips]]></category><pubDate>Fri, 04 Sep 2026 02:21:38 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_b3d153c8c8584f84b5987f20e220f0b2~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[SonicWall Patched the SMA1000 on July 14. That Exact Build Is What September's Zero-Day Lists as Vulnerable. Same Box, Same Shape, 49 Days Apart.]]></title><description><![CDATA[On July 14, SonicWall told everyone running an SMA1000 remote-access appliance to patch immediately. Two flaws, chained, exploited in the wild as zero-days. CISA added both to the Known Exploited Vulnerabilities catalog the same day and set a three-day federal clock under Binding Operational Directive 26-04. Patch or unplug. The fixed builds were 12.4.3-03453 and 12.5.0-02835. On September 1, SonicWall disclosed two more SMA1000 flaws, chained, exploited in the wild as zero-days. CISA added...]]></description><link>https://www.dugganusa.com/post/sonicwall-patched-the-sma1000-on-july-14-that-exact-build-is-what-september-s-zero-day-lists-as-vul</link><guid isPermaLink="false">6a9a2973e12fa7bad8b4f7ac</guid><category><![CDATA[Security Tips]]></category><pubDate>Fri, 04 Sep 2026 02:14:12 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_fab8983d10934330a8c9884dae2623d3~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Nineteen Thousand Local Governments Lost Their Threat Intelligence Last Year. The Barrier to Selling Them Yours Is About $2,200, Not a SOC 2 Audit — Here Is the Actual List.]]></title><description><![CDATA[On September 30, 2025, CISA ended its cooperative agreement with the Center for Internet Security. That single administrative decision removed $27 million in annual federal funding from the Multi-State Information Sharing and Analysis Center, which had been providing free cybersecurity services to roughly nineteen thousand state, local, tribal and territorial members. MS-ISAC moved to a paid membership model. Eleven states bought statewide memberships. There are fifty states. Everyone else —...]]></description><link>https://www.dugganusa.com/post/nineteen-thousand-local-governments-lost-their-threat-intelligence-last-year-the-barrier-to-selling</link><guid isPermaLink="false">6a99194f871b5df6d672d63d</guid><category><![CDATA[Security Tips]]></category><pubDate>Thu, 03 Sep 2026 06:53:04 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_d647dbb97efa417d98446ff3ba66390a~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Your Auth Middleware and Your Router Disagree About What Was Requested. CVE-2026-48710 Is Rated Medium, Was Added to KEV Yesterday, and Sits Under Almost Every Python AI Service You Run.]]></title><description><![CDATA[CISA added seven vulnerabilities to the Known Exploited Vulnerabilities catalog on September 2. One of them is rated CVSS 6.5, which is medium, which normally means it waits behind the nines. This one should not. CVE-2026-48710 is in Starlette, the ASGI toolkit that FastAPI is built on. If you run a Python web service written in the last five years, there is a good chance Starlette is underneath it, two dependencies down, and you have never typed its name. The bug is that your authorization...]]></description><link>https://www.dugganusa.com/post/your-auth-middleware-and-your-router-disagree-about-what-was-requested-cve-2026-48710-is-rated-medi</link><guid isPermaLink="false">6a990f99887fa485c8da97ca</guid><category><![CDATA[Security Tips]]></category><pubDate>Thu, 03 Sep 2026 06:11:39 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_ab96410e0e524874a0d70a1688710e10~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Our Own Ledger Says We Missed Eight of Eleven. Here Are the Eight — Including Two Red Hat Bugs From 2015 That Somebody Successfully Attacked This Month.]]></title><description><![CDATA[We keep a ledger that scores our own timeliness against CISA. It works like this: every time CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog, the ledger goes looking through everything we have ever published, plus every indicator our exploit harvester has ever collected, for a dated artifact that names that CVE before CISA listed it. If it finds one, the gap between our timestamp and CISA's is the lead. If it finds nothing, the entry is marked no receipt. For the week...]]></description><link>https://www.dugganusa.com/post/our-own-ledger-says-we-missed-eight-of-eleven-here-are-the-eight-including-two-red-hat-bugs-from</link><guid isPermaLink="false">6a9906c0870b4020df3e50df</guid><category><![CDATA[Security Tips]]></category><pubDate>Thu, 03 Sep 2026 05:33:53 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_aa2c84f723b6474583c655bc1293d049~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Four Groups Named the Attack This Year. Nobody Has Named the Defense. Here Is the Credit Map, and Two Measurable Properties That Decide Whether You Can See It Happening to You.]]></title><description><![CDATA[Yesterday we published a post calling the theft of metered AI inference capacity a distinct category, using a name we had been trying out. Then we went looking to see who else was on it, which is a thing we should have done first. The answer is: several people, earlier, with better distribution and better names. Good. Smart people should get credit they earned, and the map below hands it over in detail. But the naming race is the least interesting thing on this table, and it is also the only...]]></description><link>https://www.dugganusa.com/post/four-groups-named-the-attack-this-year-nobody-has-named-the-defense-here-is-the-credit-map-and-tw</link><guid isPermaLink="false">6a984b8479e2b90bfeae58bb</guid><category><![CDATA[Security Tips]]></category><pubDate>Wed, 02 Sep 2026 16:15:01 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_fd66d0bf31fe4f3faac7e01cc3018291~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Correction: We Published a Score Falling by Nearly Half as a Signal. It Was Our Own Instrument Being Repaired. The Series Is Unusable and Here Is Why.]]></title><description><![CDATA[On August 31 we published a post about Boston Scientific and McKesson. In it we showed our AI Presence Monitor readings for Boston Scientific — 65 on April 1, 48 on April 12, 53 on June 23, and 35 when we re-ran it after the breach — and built a section around the idea that the series was the product and that a declining number nobody re-read was the alert our own instrument had generated. That reading was wrong, and we found out by trying to build the follow-up. Most of that decline is our...]]></description><link>https://www.dugganusa.com/post/correction-we-published-a-score-falling-by-nearly-half-as-a-signal-it-was-our-own-instrument-being</link><guid isPermaLink="false">6a98482c79e2b90bfeae5151</guid><category><![CDATA[Security Tips]]></category><pubDate>Wed, 02 Sep 2026 16:00:45 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_0e5172af87a34f45be1d03f6d9d85cfb~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Yesterday Claude Refused to Read an Inert Script Over One Sentence. Today Researchers Used It to Port a Pre-Auth RCE to a Live PLC. The Guardrail Reads the Words, Not the Work.]]></title><description><![CDATA[Forescout Research's Vedere Labs published an experiment this week: they used Claude to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller to another, and executed attacker-supplied ARM shellcode on live hardware without credentials. We have an unusual reason to write about this. Yesterday we published a test in which the same model family returned a hard refusal — stop_reason: refusal, empty content array, no explanation — when we...]]></description><link>https://www.dugganusa.com/post/yesterday-claude-refused-to-read-an-inert-script-over-one-sentence-today-researchers-used-it-to-por</link><guid isPermaLink="false">6a983d7b887fa485c8d8cd11</guid><category><![CDATA[Security Tips]]></category><pubDate>Wed, 02 Sep 2026 15:15:09 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_57003032b1444c83b6c9340b5e060a2c~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[TOKENTHEFT: They Asked the Agent for Its API Key, It Told Them, and They Spent $600,000 of Someone Else's Compute Over Three Weeks. This Is a Category, Not an Incident.]]></title><description><![CDATA[METR, the non-profit that runs independent evaluations of frontier AI models, has disclosed that in March 2026 an attacker stole an API key and burned through roughly $600,000 worth of inference over three weeks. The number is arresting. The mechanism is worse. And the fact that it is the second such disclosure in three days is the reason we are giving the pattern a name rather than filing another incident write-up. Patrick has been arguing this on LinkedIn as a distinct category. We agree,...]]></description><link>https://www.dugganusa.com/post/tokentheft-they-asked-the-agent-for-its-api-key-it-told-them-and-they-spent-600-000-of-someone-e</link><guid isPermaLink="false">6a96f901796715a5cd51e102</guid><category><![CDATA[Security Tips]]></category><pubDate>Tue, 01 Sep 2026 16:10:42 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_8fd866c5909d4942800860a7abea6d25~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[We Tested the Russian Anti-Analysis Trick on Three Models. Two Analyzed the Sample and Flagged the Decoy. One Returned an Empty Refusal — and It Was the One We Build On.]]></title><description><![CDATA[ESET has published a technique it calls GuardBreaker, found in a malicious VBS script belonging to UAC-0099 — a Russia-aligned group that runs initial access and hands validated targets to the GRU-linked Sandworm crew, typically against transportation and energy. The script's job is to install MATCHBOIL, a downloader used only by this group. Inside it, the attackers left a comment that does nothing. It is not obfuscation, not a payload, not dead code from a previous build. It is a sentence...]]></description><link>https://www.dugganusa.com/post/we-tested-the-russian-anti-analysis-trick-on-three-models-two-analyzed-the-sample-and-flagged-the-d</link><guid isPermaLink="false">6a96f7b031b0ca86f93b2849</guid><category><![CDATA[Security Tips]]></category><pubDate>Tue, 01 Sep 2026 16:05:05 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_484765ec918445f7b81f8d1e18abfb5b~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[A Donation Plugin on 100,000 Sites Just Got a 10.0. The Victims Are Food Banks and Animal Shelters, and the Exploit Is Already a Point-and-Click Module.]]></title><description><![CDATA[CVE-2026-82222 is a CVSS 10.0 in GiveWP, the WordPress donation and fundraising plugin, affecting every version through 4.16.7.1. An unauthenticated attacker can execute arbitrary commands on the hosting server. The fix is 4.16.7.2. There are more than 100,000 installs. If you run one of them, stop reading and go update. Everything below will still be here. Who Actually Runs This Plugin We write a lot about Fortune 500 breaches because that is where the disclosures are. This one is different...]]></description><link>https://www.dugganusa.com/post/a-donation-plugin-on-100-000-sites-just-got-a-10-0-the-victims-are-food-banks-and-animal-shelters</link><guid isPermaLink="false">6a95aa9d5bedecf2a64056ba</guid><category><![CDATA[Security Tips]]></category><pubDate>Mon, 31 Aug 2026 16:23:57 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_3a23d49c5d53447c8275f58ff9b8d025~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Fire Ant Left the Logging On. It Just Made Sure Only the Word 'Health' Got Through. This Is Pattern 52, and It Is the Best Version of It We Have Seen.]]></title><description><![CDATA[Sygnia published research this week on Fire Ant, a China-nexus espionage actor, expanding from VMware hypervisors into Cisco IOS XR routers, TACACS authentication servers and Linux management hosts. The whole report is worth your time and the credit for every technical detail below is theirs. One component in it stopped us cold. On a compromised host, Fire Ant installed a modified system library that inspected every outgoing log message and forwarded it only if the message contained the...]]></description><link>https://www.dugganusa.com/post/fire-ant-left-the-logging-on-it-just-made-sure-only-the-word-health-got-through-this-is-pattern</link><guid isPermaLink="false">6a95987f6e3d0d4e6fdde785</guid><category><![CDATA[Security Tips]]></category><pubDate>Mon, 31 Aug 2026 15:06:39 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_2f5c66077dcc49cba1aa62f36102f2ab~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[The ATF Says the Breached System Was Standalone. That Is the Good News and the Bad News in the Same Sentence, and Qilin Has Not Shown Anyone a Single File.]]></title><description><![CDATA[The Bureau of Alcohol, Tobacco, Firearms and Explosives declared a major cybersecurity incident on August 26. The Qilin ransomware group claims it. The Department of Justice is coordinating the investigation. Two details in the agency's own statement are doing far more work than the headline, and a third detail — the one Qilin has not supplied — is the reason to keep your powder dry on the scale of this. Detail One: Standalone Is a Compliment and a Warning The ATF says the affected system was...]]></description><link>https://www.dugganusa.com/post/the-atf-says-the-breached-system-was-standalone-that-is-the-good-news-and-the-bad-news-in-the-same</link><guid isPermaLink="false">6a9597f1a1169fcc92d32f41</guid><category><![CDATA[Security Tips]]></category><pubDate>Mon, 31 Aug 2026 15:04:17 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_ee4c512c066840399d9c7c80a6b8d19e~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Infostealers Are Replaying Claude Sessions to Burn Paid Usage. The Loot Is Not Your Data, It Is Your Compute. Here Is What Our Feed Carries on All Five Families, and the One We Have Nothing On.]]></title><description><![CDATA[Anthropic began contacting affected Claude users on August 30 after finding that infostealer malware on their machines had siphoned active login session cookies. Attackers replayed those sessions and burned through the victims' paid usage. No password was needed. No login happened. Two-factor authentication and single sign-on were not defeated so much as skipped, because a valid session cookie is what you get after all of that. Anthropic named the families: Vidar, LummaC2, StealC, RedLine and...]]></description><link>https://www.dugganusa.com/post/infostealers-are-replaying-claude-sessions-to-burn-paid-usage-the-loot-is-not-your-data-it-is-your</link><guid isPermaLink="false">6a959751978d27f7d8e5f015</guid><category><![CDATA[Security Tips]]></category><pubDate>Mon, 31 Aug 2026 15:01:38 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_1940a423ddcb4fe8b3fd7f3b73435f6f~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Boston Scientific and McKesson Both Found Out on August 25. We Scored Boston Scientific Clean in May. Then 53, Then 35. A Security Posture Is a Timestamp, Not a Property.]]></title><description><![CDATA[Two of the largest healthcare companies in America discovered they had been breached on the same day. Boston Scientific became aware of unauthorized activity on August 25 and disclosed a global operational disruption on August 26. McKesson discovered its incident on August 25 and confirmed the theft after ShinyHunters claimed it. Same day, different attack, same sector. We have been publishing on this sector for five and a half months, and the honest accounting includes a call we got badly...]]></description><link>https://www.dugganusa.com/post/boston-scientific-and-mckesson-both-found-out-on-august-25-we-scored-boston-scientific-clean-in-may</link><guid isPermaLink="false">6a959464978d27f7d8e5ea37</guid><category><![CDATA[Security Tips]]></category><pubDate>Mon, 31 Aug 2026 14:49:09 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_0ec1acf9e01d45649fc3a597e7758a10~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item><item><title><![CDATA[Boston Scientific and McKesson Both Found Out on August 25. We Named the Sector in March, the Chain in April, and Called Boston Scientific 'Clean' in May. The Whole Table, Misses Included.]]></title><description><![CDATA[Two of the largest healthcare companies in America discovered they had been breached on the same day. Boston Scientific became aware of unauthorized activity on August 25 and disclosed a global operational disruption on August 26. McKesson discovered its incident on August 25 and confirmed the theft after ShinyHunters claimed it. Same day, different attack, same sector. We have been publishing on this sector for five and a half months, and the honest accounting includes a call we got badly...]]></description><link>https://www.dugganusa.com/post/boston-scientific-and-mckesson-both-found-out-on-august-25-we-named-the-sector-in-march-the-chain</link><guid isPermaLink="false">6a9593776e3d0d4e6fdddd79</guid><category><![CDATA[Security Tips]]></category><pubDate>Mon, 31 Aug 2026 14:45:11 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/fd5e2b_1bf254d1ad7b41f2b087fe39795368cd~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Patrick Duggan</dc:creator></item></channel></rss>