top of page



A Fourth Indirect-Trust Vector Just Surfaced. Polymarket Bot Stole Wallet Keys Through A Hijacked Verified GitHub Org. Also We Now Have ShinyHunters' Leak-Site Onion.
I wrote a blog this morning naming three indirect-trust supply-chain vectors that hit corporate developers in May 2026 — Laravel-Lang tag-pointers, Megalodon workflow files, Ghost CMS themes — and called it a doctrine that the criminal marketplace had crossed into operational use. Six hours later, while back-filling adversary profiles into our IOC index, our extractor surfaced an unexpected URL inside a TeamPCP-related research article: a Cloudflare Workers endpoint at...
Patrick Duggan
May 244 min read


Eight Distinct USPS Phishing Domains Live In Our IOC Feed Right Now. The Tracking-Number Scam Is The Consumer's Megalodon.
DugganUSA's multi-axis brand-impersonation watch list put globaluspslogistics.com in the top tier this morning at composite confidence 0.85, single-axis pattern-49 detection. The watch list is the synthesis layer; the IOC index is the raw substrate. A quick cross-query against the substrate returns eight distinct USPS-themed phishing infrastructures currently live in our feed, all sourced from OpenPhish's automated detection pipeline, all classified as active phishing, all ru
Patrick Duggan
May 244 min read


Anthropic's Project Glasswing Just Cleared Ten Thousand High-Severity Vulnerabilities In One Month. The Partnership Asymmetry Is Real.
Anthropic disclosed on Friday that Project Glasswing, their cybersecurity vulnerability research initiative launched last month, has now produced more than ten thousand high- or critical-severity vulnerabilities across some of the most systemically important software in the world. Ten thousand findings in a single month from an AI-assisted research program is the kind of throughput that is difficult to characterize in conventional terms. The number is large enough that the co
Patrick Duggan
May 243 min read


Three Indirect-Trust Vectors In Three Weeks. The Attacker's New Doctrine Is The Artifact Layer Nobody Audits.
Over the last three weeks DugganUSA's IOC index has carried receipts on three independent supply-chain compromises that, on the surface, look like three different stories. The Laravel-Lang credential stealer on May 22. The Megalodon mass GitHub Actions workflow poisoning on May 18. The Ghost CMS remote code execution disclosed earlier in May and re-surfaced this weekend with a publicly available proof-of-concept exploit. Three packaging ecosystems, three different attacker cl
Patrick Duggan
May 244 min read


We Had Megalodon's C2 Forty-Nine Days Before It Bit. Here Are The Three Detectors We Just Wired To Catch The Next One.
I published a blog yesterday about Megalodon, the mass GitHub Actions workflow-poisoning campaign that compromised 5,561 repositories in six hours on May 18, 2026. The headline I led with was that DugganUSA's IOC index carried the command-and-control endpoint at 216.126.225.129 before the campaign was publicly named by SafeDep, StepSecurity, OX, the Hacker News, and the rest. That was true. It was also a serious undercount of the actual receipt. Tonight's deeper hunt against
Patrick Duggan
May 234 min read


Command and Control Over Blockchain. Two Actors, One Year, A New Category That Cannot Be Taken Down.
There are exactly two Internet Computer Protocol blockchain canister command and control endpoints in DugganUSA's IOC index as of today. The first, cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io, was indexed by SSL Blacklist on April 23, 2026, attributed to an unnamed criminal actor. The second, tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io, was indexed independently on May 22, 2026, attributed to TeamPCP, the cluster behind the Megalodon GitHub Actions mass-poisoning campaign that ate 5,
Patrick Duggan
May 234 min read


Netflix Is At The Top of Our Brand Pyramid Today. Two Independent Axes. The Math Says Watch Tonight.
DugganUSA's brand-impersonation watch list ran its multi-axis aggregation this afternoon. Thirty candidate brands across five orthogonal signal axes. The top of the pyramid today is Netflix at 0.95 composite confidence, the only brand at that confidence band, and the only brand currently hitting two independent axes at the elevated level. The math is not a forecast; it is a description of two independent measurements that converged on the same target without coordination. The
Patrick Duggan
May 234 min read


Megalodon Ate 5,561 GitHub Repos in Six Hours. We Had the C2 in the Feed Before It Had a Name.
Between 11:36 and 17:48 UTC on May 18, 2026, a single automated campaign pushed 5,718 malicious commits to 5,561 GitHub repositories in six hours. The campaign was named Megalodon four days later by SafeDep, StepSecurity, OX Security, and a half-dozen other researchers who independently dissected the attack pattern. The malicious payload injected into each repository's .github/workflows/ directory is a base64-encoded bash loader that exfiltrates CI secrets, AWS and GCP and Az
Patrick Duggan
May 234 min read


The Laravel-Lang Credential Stealer Never Touched the Official Repo. It Used GitHub Tags As Misdirection.
On May 22, 2026, a credential-stealing supply chain attack lit up the Laravel/PHP ecosystem. By May 23, security researchers at Aikido, Socket, and the Hacker News had published the dissection. The headline number is 700 — as in 700-plus version tags rewritten across three widely used packages in the Laravel-Lang organization. The number that matters more is zero, as in the number of malicious commits ever pushed to the official repositories. The attacker did not compromise t
Patrick Duggan
May 234 min read


The FBI Just Named the VPN Dozens of Ransomware Groups Share. The Quiet Part Is What That Means.
The FBI confirmed this week that dozens of ransomware groups have been routing reconnaissance, initial access tooling, and intrusion traffic through a single commercial VPN service called First VPN. The advisory frames it as a notable operational pattern. The structural read is more interesting than that. When the FBI names a shared piece of adversary infrastructure, the actual disclosure is not that the bad guys use VPNs — that has been true for two decades — but that defend
Patrick Duggan
May 224 min read


Verizon DBIR 2026 Just Made Our Pattern 53 Industry Data — Vulnerability Exploitation Overtakes Credential Theft
May 22, 2026. Verizon dropped the 2026 Data Breach Investigations Report this morning. The headline finding, the line every CISO will quote in the next...
Patrick Duggan
May 224 min read


Edges Are All Over Now — Why The Decision Boundary Is The New Perimeter
May 21, 2026. Earlier today we shipped a post called Edge-Appliance Week — five vendor RCEs in fourteen days, the foot in the door is every foot. That post...
Patrick Duggan
May 215 min read


Edge-Appliance Week — Five Vendor RCEs In Fourteen Days, And The Foot In The Door Is Every Foot
May 21, 2026. CISA's Known Exploited Vulnerabilities catalog added three entries today. Two of them are edge-appliance vendors — Ivanti and Fortinet. In the...
Patrick Duggan
May 214 min read


The Week The Defenders Became The Supply Chain — TanStack, CISA, And The Pyramid We Wrote Six Weeks Ago
May 21, 2026. Three days ago we shipped a soft-surface-bleed post about three vendors getting cracked open while the perimeter held. Last night we shipped a...
Patrick Duggan
May 214 min read


Defender Is The Attack Surface Now — Five CVEs, Thirty Days, Three On KEV
May 20, 2026. CISA added two more Microsoft Defender vulnerabilities to the Known Exploited Vulnerabilities catalog today. CVE-2026-41091 is an...
Patrick Duggan
May 203 min read


Three Soft Surfaces Bled Today — The Perimeter Held Every Time
May 20, 2026. Three separate incidents on the wire today, three separate vendors, three separate threat actors. Same shape on all of them. The hardened...
Patrick Duggan
May 203 min read


Four Hours From Disclosure To Exploitation. PraisonAI Just Set The New Floor.
CVE-2026-44338 in PraisonAI was disclosed publicly on May 14, 2026. Threat actors were observed attempting to exploit it within four hours. This is the new floor. PraisonAI is an open-source framework for building agentic AI applications. The vulnerability allowed remote code execution against PraisonAI instances. The disclosure-to-weaponization gap of four hours is approximately one hundred and sixty-eight times shorter than the gap commonly cited in security writeups from 2
Patrick Duggan
May 204 min read


Dirty Frag Plus NGINX Rift Plus CVE-2026-43284. The May 2026 Kill Chain Nobody Is Calling A Kill Chain.
The cybersecurity press names individual CVEs because individual CVEs make for clean headlines. The defender press should also be naming exploit chains, because exploit chains are what actually compromise production environments. May 2026 delivered a three-CVE chain that Security Boulevard called "a reliable, race-free, forensically quiet kill chain from the public internet to root." This post unpacks each CVE, how they chain, and why a chain-aware detection posture is the on
Patrick Duggan
May 205 min read


Trellix Got Breached. Attackers Stole The Code Powering Their Security Tools. The Cobbler's Children Have An Inventory Problem Now.
This week, the security vendor Trellix disclosed that attackers had gained unauthorized access to the code powering the company's security tools. Not customer data. Not employee records. The source code of the tools Trellix sells to defenders. Trellix descended from the 2022 merger of McAfee Enterprise and FireEye, two of the most storied security vendors in the industry. McAfee was breached in 2010. FireEye was breached in 2020 by the SolarWinds operator — the breach that ta
Patrick Duggan
May 205 min read


🔺 CONSPIRACY THEORY Newsletter Vol. 49: The Embedder Is The Progeny
🔺 CONSPIRACY THEORY 🔺 The Newsletter They Don't Want You To Read Volume 49 | May 20, 2026 | $2.00 (cash only, exact change, no tracking, do NOT use Venmo) ――――――――――――――――――――― ATTENTION SUBSCRIBERS: If you registered for the STIX feed this week, you're already in the system. Yes, that one. Yes, the analytics ARE logged. The transparency goes one way. No nose biting, Jerry. ――――――――――――――――――――― THIS WEEK'S PATTERN: THE EMBEDDER IS THE PROGENY Stay with me. July eighth, 197
Patrick Duggan
May 195 min read
bottom of page