top of page



A Donation Plugin on 100,000 Sites Just Got a 10.0. The Victims Are Food Banks and Animal Shelters, and the Exploit Is Already a Point-and-Click Module.
CVE-2026-82222 is a CVSS 10.0 in GiveWP, the WordPress donation and fundraising plugin, affecting every version through 4.16.7.1. An unauthenticated attacker can execute arbitrary commands on the hosting server. The fix is 4.16.7.2. There are more than 100,000 installs. If you run one of them, stop reading and go update. Everything below will still be here. Who Actually Runs This Plugin We write a lot about Fortune 500 breaches because that is where the disclosures are. This
Patrick Duggan
Aug 315 min read


Fire Ant Left the Logging On. It Just Made Sure Only the Word 'Health' Got Through. This Is Pattern 52, and It Is the Best Version of It We Have Seen.
Sygnia published research this week on Fire Ant, a China-nexus espionage actor, expanding from VMware hypervisors into Cisco IOS XR routers, TACACS authentication servers and Linux management hosts. The whole report is worth your time and the credit for every technical detail below is theirs. One component in it stopped us cold. On a compromised host, Fire Ant installed a modified system library that inspected every outgoing log message and forwarded it only if the message co
Patrick Duggan
Aug 316 min read


The ATF Says the Breached System Was Standalone. That Is the Good News and the Bad News in the Same Sentence, and Qilin Has Not Shown Anyone a Single File.
The Bureau of Alcohol, Tobacco, Firearms and Explosives declared a major cybersecurity incident on August 26. The Qilin ransomware group claims it. The Department of Justice is coordinating the investigation. Two details in the agency's own statement are doing far more work than the headline, and a third detail — the one Qilin has not supplied — is the reason to keep your powder dry on the scale of this. Detail One: Standalone Is a Compliment and a Warning The ATF says the af
Patrick Duggan
Aug 315 min read


Infostealers Are Replaying Claude Sessions to Burn Paid Usage. The Loot Is Not Your Data, It Is Your Compute. Here Is What Our Feed Carries on All Five Families, and the One We Have Nothing On.
Anthropic began contacting affected Claude users on August 30 after finding that infostealer malware on their machines had siphoned active login session cookies. Attackers replayed those sessions and burned through the victims' paid usage. No password was needed. No login happened. Two-factor authentication and single sign-on were not defeated so much as skipped, because a valid session cookie is what you get after all of that. Anthropic named the families: Vidar, LummaC2, St
Patrick Duggan
Aug 315 min read


Boston Scientific and McKesson Both Found Out on August 25. We Scored Boston Scientific Clean in May. Then 53, Then 35. A Security Posture Is a Timestamp, Not a Property.
Two of the largest healthcare companies in America discovered they had been breached on the same day. Boston Scientific became aware of unauthorized activity on August 25 and disclosed a global operational disruption on August 26. McKesson discovered its incident on August 25 and confirmed the theft after ShinyHunters claimed it. Same day, different attack, same sector. We have been publishing on this sector for five and a half months, and the honest accounting includes a cal
Patrick Duggan
Aug 3110 min read


Boston Scientific and McKesson Both Found Out on August 25. We Named the Sector in March, the Chain in April, and Called Boston Scientific 'Clean' in May. The Whole Table, Misses Included.
Two of the largest healthcare companies in America discovered they had been breached on the same day. Boston Scientific became aware of unauthorized activity on August 25 and disclosed a global operational disruption on August 26. McKesson discovered its incident on August 25 and confirmed the theft after ShinyHunters claimed it. Same day, different attack, same sector. We have been publishing on this sector for five and a half months, and the honest accounting includes a cal
Patrick Duggan
Aug 317 min read


If the Indicator Was in the Feed and Your Firewall Pulled the Feed, the Attack Chain Broke by Itself. Nobody Wrote an Article About It. That Is the Entire Product.
Earlier today we published every CVE CISA cataloged in the last month — all thirty — with our own hit rate attached. Early on seven, nothing at all on seventeen. The number that matters in that table is not the lead time. It is what happens during the lead time without anybody doing anything. If an indicator is in the feed, and your firewall or SIEM pulls the feed on a schedule, the block is already in place before you have heard of the CVE. No analyzt reads an advisory. No t
Patrick Duggan
Aug 277 min read


We Checked Every CVE CISA Catalogued in the Last Month. All Thirty. We Were Early on Seven, Late on Three, and Had Absolutely Nothing on Seventeen — Here Is the Whole Table.
Threat intelligence vendors publish the wins. Somebody catches one thing early, it becomes a case study, and the case study never mentions the other twenty-nine. So here is the whole month. Every CVE added to the CISA Known Exploited Vulnerabilities catalog between 28 July and 27 August 2026 — thirty of them — checked against our own indicator index for a receipt that predates the listing. Nothing excluded, nothing selected, no cherry-picking. Outcome Count Share We had a rec
Patrick Duggan
Aug 275 min read


He Didn't Jailbreak the AI. He Told It the Engagement Was a Test, and Breached Seven Companies. Then He Left the Chat Log Where Investigators Could Read It.
A Russian-speaking Aurora ransomware affiliate compromised more than 20 organizations across nine countries between April and July 2026, reaching domain-level or interactive access in at least 17 of them. Four victims ended up named on Aurora's leak site. Manufacturing, food, agriculture, professional services. He used Cursor, the AI coding assistant, to plan the intrusions and the Active Directory escalation. In Russian. Two things about that are worth your time. Neither of
Patrick Duggan
Aug 276 min read


They Published 24 npm Packages That Nobody Was Ever Meant to Install. The Package Was Never the Weapon — the Registry Was the Free Hosting, and the Fake CAPTCHA Runs Cloudflare's Real One.
Every npm supply-chain story you have read works the same way. The package is the weapon. It runs a post-install script, steals a token, backdoors a dependency, worms onward to the next maintainer. The victim is a developer, and the defence is install hygiene — pin your versions, audit your dependencies, run with --ignore-scripts. OX Security has documented a cluster of 24 npm packages that inverts all of that. Nobody is meant to install them. No developer is involved at any
Patrick Duggan
Aug 265 min read


Everyone Will Write About the Clever Trick That Took 283 Cameras. The Default Password Took 12,324. Operation CameraSwarm Is a Lesson in Reading Your Own Numbers.
Hunt.io published research on Operation CameraSwarm: 14,530 Dahua devices compromised between 17 June and 22 July 2026, concentrated in Ukraine and Russia. The campaign used three methods, and the write-ups — reasonably — lead with the most interesting one, a peer-to-peer relay abuse that turns the vendor's own infrastructure into a route past your firewall. Here is how the 14,530 actually breaks down: Method Devices Share Credential attacks 12,324 84.8% Authentication bypass
Patrick Duggan
Aug 264 min read


Your Stolen iPhone Calls You Back, in a Voice That Says It's Apple Support. Lost Mode Handed Over Your Number, and the AI on the Line Costs Less Per Call Than the Thief's Bus Fare.
Somebody steals your iPhone. It locks. Activation Lock means the device is worth roughly its weight in aluminium, because it cannot be paired to a new owner without your Apple ID. So you do the correct thing. You put it in Lost Mode, which displays a message and a contact number, so that an honest finder can get it back to you. You have just told the thief how to reach you. And within hours a voice with an Apple Support script will call that number, in English, Spanish or Por
Patrick Duggan
Aug 265 min read


On 31 July We Said Gitea's Login Wall Wasn't a Wall. On 25 August CISA Listed It as Actively Exploited. The Bug Needed an Account — and Gitea Hands Those Out at the Door.
On 31 July we published a post with an argument in the title: "Gitea Shipped a 9.8 That Needs an Account. Gitea Also Ships With Anyone Being Able to Make One." On 25 August, CISA added [CVE-2026-60004](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-60004) to the Known Exploited Vulnerabilities catalogue. Reported attacks are dropping a miner-like payload. Twenty-five days. And more to the point: the thing we argued was the weak part is the thing that broke.
Patrick Duggan
Aug 265 min read


You Were Told to Read the Notebook Before You Run It. In marimo, Opening It Was Already the Exploit — and the Command Came Out of the File's Own Metadata.
Every safety instruction anyone has ever given about notebooks rests on one assumption: you can look before you leap. Open the file, read the cells, decide whether you trust it, then run it. Reading is safe. Running is the risk. That is the whole mental model, and it is why nobody thinks twice about opening a notebook a colleague sent them. [CVE-2026-75149](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-75149) deletes that assumption. In marimo before 0.23.
Patrick Duggan
Aug 255 min read


They Let You Finish Your Real MFA. That Was the Point. Mirage2FA Took 4,532 Sessions From 9,426 Attempts, and the Phishing Mail Came From a Company You Actually Do Business With.
Nine thousand four hundred and twenty-six email addresses targeted. Four thousand five hundred and thirty-two potentially compromised. That is a 48 percent success rate against organisations that, overwhelmingly, had multi-factor authentication switched on. Roughly one in two. If you have ever sat in a meeting where someone said "we rolled out MFA, we're covered on phishing," this is the number that belongs on the next slide. The platform is Mirage2FA, also tracked as LinXcod
Patrick Duggan
Aug 255 min read


The Signature Failed to Verify, So It Was Accepted. That Is Not a Typo — It Is CVE-2026-15981, It Is Being Exploited Right Now, and We Had the Detection Rule Three Weeks Before Anyone Saw It Used.
PHP has a function that checks cryptographic signatures. It does not return true or false. It returns three things: 1 if the signature is valid, 0 if it is invalid, and −1 if OpenSSL fell over and could not perform the check at all. The miniOrange SAML plugin tested that result with a loose boolean check. In PHP, −1 is truthy. So the one answer that means I have no idea whether this is genuine, something went wrong was read as this is genuine. Send a signature malformed enoug
Patrick Duggan
Aug 256 min read


Their Command-and-Control Layer Is Two Thousand Hacked Small Businesses. We Fed the Hashes and Refused to Blocklist a Single Domain — Here Is Why That Is Not Squeamishness.
Check Point Research unmasked an operation called StopAndProtect on 19 August, and they got it the way you always eventually get someone: the operators made a mistake and left their own server readable. The numbers are: roughly 2,000 hacked WordPress sites, 6,000-plus unique victim IP addresses, around 31,000 screenshots and 700-plus archives of stolen data, collected between mid-May and the end of July 2026. We had zero attributed indicators for this campaign in our feed whe
Patrick Duggan
Aug 246 min read


A 9.4 That Lets Anyone on the Network Command a Spacecraft. NASA Shipped the Fix. Nobody Assigned It a Number — So Your Scanner Will Never See It, and Neither Did Ours.
There is a vulnerability chain in NASA/JPL software that lets an unauthenticated attacker on the network issue arbitrary commands to a spacecraft and instrument command bus. It is rated CVSS 9.4. It was disclosed on 18 August 2026. The fix shipped. The advisory is public. It has no CVE. Not "a CVE pending." Not "a CVE we are waiting on." The advisory says it plainly: no CVE has been assigned at the time of writing. Which means that for every defender whose vulnerability manag
Patrick Duggan
Aug 246 min read


GitLab Patched It Monday. Our Harvester Had the Exploit Endpoints Tuesday. watchTowr Saw It Hitting Honeypots Friday. It Is Still Not in KEV. Here Is What to Grep.
[CVE-2026-19478](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-19478) is a code-injection flaw reached through a GraphQL directive in GitLab Community and Enterprise Edition. CVSS 9.4. Unauthenticated, remote, no user interaction. An attacker who has never logged in can modify or delete user data and public projects. GitLab patched it on 17 August 2026. Our exploit harvester collected public proof-of-concept code and emitted detection rules for it on 18 Au
Patrick Duggan
Aug 245 min read


How Armour Actually Works — and Why Ours Is Shaping Up to Be One of the Best. Somebody Attacked Us While I Was Writing This. Here Is the Whole Receipt.
Stop letting fear stop you from being secure. That is the whole argument, and the reason it needs making is that the security industry has a commercial interest in you believing the opposite — that defence is a thing you buy at enterprise scale, that it costs hundreds of thousands of dollars, and that attempting it with less is worse than not trying. None of that is true. Armour built right is cheap, and the expensive part was never the armour. While I was writing this paragr
Patrick Duggan
Aug 2412 min read
bottom of page