top of page



Six Times in Five Years, CISA Has Listed a Bug Whose Only Job Was Defeating the Fix for the Last One. Two of Them Landed in the Same Week.
I went looking for something small this morning and found a number worth publishing.
Patrick Duggan
4 days ago6 min read


81 Million Login Attempts Came Over IPv6. Then We Audited Our Own Signup Gate and Found It Cannot See IPv6 Either.
Between June 12 and June 26, a password spray campaign against Azure CLI sign-ins generated more than 81 million login attempts. Huntress reported at least...
Patrick Duggan
4 days ago6 min read


3.7 Million Patients, a Six-Day Window in an AWS Account, and Five Months Later Nobody Has Claimed It. That Is the Alarming Part.
CareCloud confirmed today that its breach affects more than 3.7 million people — the fifth-largest theft of health data in 2026 so far.
Patrick Duggan
4 days ago5 min read


Medusa Pays Access Brokers Up to $1 Million and Has Now Passed 500 Victims. The New Advisory Names Healthcare Specifically.
The FBI, CISA and HHS updated advisory AA25-071A on August 18 with FBI investigative findings current to April 2026. Two things in the update deserve more...
Patrick Duggan
4 days ago5 min read


We Published the Exact Hunt Pattern on June 26. Clop Just Listed 43 Windchill Victims Including Shell, GE and Philips.
On August 17 the Clop extortion group listed 43 new victims on its leak site, all claimed via internet-exposed PTC Windchill and FlexPLM instances,...
Patrick Duggan
4 days ago5 min read


Microsoft Patched a Defender Bug in July. The Bypass Dropped August 12. The Mitigation Broke Scanning. There Is Still No Fix.
There is a particular kind of failure that only happens to security products, and Defender is having all of it at once this month.
Patrick Duggan
4 days ago5 min read


They Didn't Need a Zero-Day. They Needed a Ten-Year-Old Python Library and a Chatbot.
CISA, NSA, FBI, DOE and EPA published AA26-231A today: "Defending Against an Active Threat to Siemens S7 Series PLCs." Five agencies on one advisory about one product family is not a routine Patch Tuesday note. That is a bell being rung. Here is the sentence that matters, and almost nobody is going to quote it correctly. The actors are building tooling from snap7 and python-snap7 — open-source industrial automation libraries — combined with AI-assisted scripting, to produce c
Patrick Duggan
4 days ago6 min read


CISA Said 'Known Exploited' on Monday. The Exploit Had Been on GitHub for Twelve Days, and Nobody Has Ever Scanned Us for It.
When CISA adds a CVE to the Known Exploited Vulnerabilities catalogue, the date it stamps on that entry is the day CISA could confirm exploitation. Everybody reads it as the day exploitation started. Those are not the same clock, and the gap between them is where your patch window actually lives. We can measure the gap, because we happen to keep both clocks running. The three columns For every CVE in KEV we hold, or can hold, three dates. t0 — the KEV listing. CISA's, public,
Patrick Duggan
5 days ago5 min read


Every Registration Control We Shipped, They Answered Within Two Days. So We Stopped Chasing the Operator and Started Detecting the Shape.
Most detection writing describes a control and stops there. The interesting part is never the control — it is what the other side does about it, and how fast. We got four days of that this week against a single operator, on our own free-tier registration form, and every observation below is our telemetry rather than somebody else's report. The setup On August 15 an audit found that 26 of the 103 API keys we had ever issued — 25% of every registration in our history — belonged
Patrick Duggan
5 days ago9 min read


SleeperGem Borrowed Seven Years of Trust. Four Weeks Later StubMaker Didn't Bother, and Our Ruby Deny-List Was Three Packages Long.
Four weeks ago a RubyGem called Dendreo shipped a malicious version from a maintainer account that had been quiet since October 2020. We wrote about it, because the dormancy was not incidental to the attack — it was the attack. Seven years of accumulated trust, spent all at once. We also ran our own package-reputation scanner against it that morning and published what it said, which was allow. On August 15, sixteen more malicious gems arrived. This time nobody borrowed any tr
Patrick Duggan
5 days ago5 min read


CISA Catalogued the Cisco Door and Left the Ladder - A CVSS 10.0 Root Bug With Two Public Exploits and No KEV Entry
At one minute past midnight our exploit harvester fired an alert. A second independent public proof-of-concept had appeared for CVE-2026-20079, a vulnerability in Cisco Secure Firewall Management Center. We already had the first one, harvested ten days earlier. What made the second interesting was not the exploit. It was what happened when we checked whether CISA had catalogued the vulnerability. It had not. It still has not. Three vulnerabilities, one product, one very odd p
Patrick Duggan
6 days ago4 min read


Someone Is Hiding Instructions in Your CLAUDE.md - Here Is a Free Tool That Finds Them
If you use Claude Code, Cursor, Copilot, Cline or Windsurf, there is a file in your repository that your AI agent reads before it does anything else. It is called CLAUDE.md, or .cursorrules, or copilot-instructions.md. It is the standing brief. Every session, every invocation, the model reads it and takes it as direction. It is also, in most repositories, a file nobody reviews carefully. It is prose, not code. It does not run. It has no tests. When it shows up in a pull reque
Patrick Duggan
6 days ago5 min read


Would a Threat Feed Have Saved McDonald's? Probably Not - And Here Is Exactly Where One Would
On 16 August 2026, Hudson Rock's InfoStealers reported that an actor calling themselves TheHatman is selling internal employee directories said to be pulled from enterprise Azure and Entra portals using compromised credentials. The list of named organisations is not small: McDonald's at roughly 1.7 million records, TCS at 800,000, Vodafone at 425,000, HCL Technologies, InterContinental Hotels, Kyndryl, Gap, Hexaware, Wyndham. Around 3.6 million records in total, if the seller
Patrick Duggan
Aug 165 min read


The Next Big Thing - What a 1975 Punk Record Taught Us About Security Vendor Math
In March 1975, a year before the Ramones put out a record, five guys from the Bronx and Queens released an album called Go Girl Crazy! The first track was called "The Next Big Thing," and it opened with a boast — the singer explaining, at length, that he was about to be enormous. He was not. The Dictators never got big. The record sold badly. Epic dropped them. They were also, by fairly broad agreement now, one of the first punk bands in the world. Half of what CBGB became in
Patrick Duggan
Aug 166 min read


How I Learned to Stop Worrying and Publish the Feed - Dr. Strangelove as a Threat Intelligence Manual
Stanley Kubrick released Dr. Strangelove or: How I Learned to Stop Worrying and Love the Bomb in 1964. It is a film about an automated retaliation system, a communications gate that fails at the worst possible moment, a room full of confident men reading a board that is already wrong, and a conspiracy theory built entirely out of correlation. We spent this week measuring our own automated blocking system. Every single one of those turned out to be a documented failure mode we
Patrick Duggan
Aug 167 min read


We Measured Our Own Free Edge Shield. The Blocklist and the Shield Catch Almost Entirely Different Attackers.
We run a threat intelligence platform, and we defend it with something that costs us almost nothing: a small script running on Cloudflare's edge, fed by a list of addresses our own feed rates as high confidence. No appliance. No agent. No console. No analyst watching a screen. We call it the edge shield, and the honest question we had never properly answered was whether it actually works, or whether it is security theatre that happens to be cheap. So we measured it. This is w
Patrick Duggan
Aug 167 min read


SAP Shipped a Fix for a CVSS 10.0 on Tuesday. Somebody Was Exploiting It by Friday — and There Is Still No Public Exploit to Copy.
[CVE-2026-58231](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-58231) is a 10.0. Not a 9.8 — the actual ceiling. SAP patched it in Commerce Cloud on patch day. Defused researchers saw the first exploitation attempts hit their honeypots three days later. And as of writing there is no public proof-of-concept. That last fact is the interesting one, and it is what this post is about. The flaw It is in the Commerce Cloud Data Hub Adapter, affecting COM_CLOUD ve
Patrick Duggan
Aug 154 min read


Six Supplier Breaches in One Week, and ShinyHunters Is in Two of Them. The Metabase Bug That Took ShipMonk Was Exploited Five Days Before CISA Listed It.
Six organisations disclosed breaches this week and not one of them was breached. Their suppliers were. Listed separately they read as an unlucky week. Put the dates and the mechanisms side by side and two things fall out: the same crew is behind at least two of them, and one of the entry points is a vulnerability we wrote about on Tuesday — exploited five days before CISA got around to cataloguing it. The week Trezor — 13,689 customers exposed. Not through Trezor. Through Shi
Patrick Duggan
Aug 155 min read


A Researcher Posted a GeoServer Zero-Day on X at 10:46 UTC. Exploitation Started Within Hours. It Scores 9.8 and It Still Has No CVE Number.
On August 12, 2026, at 10:46 UTC, a researcher going by @q1uf3ng posted a GeoServer zero-day to X. Within hours, exploitation attempts were being observed in the wild. The flaw carries a CVSS of 9.8. It has no CVE number. It has a GitHub advisory identifier — GHSA-mqjf-5f49-2fjh — and that is the whole of its official naming. We run a standing beat on exactly this tier, so here is the honest read on what it is, what the timeline tells you, and why the missing identifier matte
Patrick Duggan
Aug 154 min read


A Reader Asked for MISP. We Shipped It in a Day — and the First Version Would Have Republished Spamhaus's Work Under Our Name.
We now publish a MISP feed. Point a MISP instance at https://analytics.dugganusa.com/api/v1/stix-feed/misp/ — Sync Actions, Feeds, Add, format "MISP Feed" — with an API key. It is live as of today, and free. The more useful half of this post is what went wrong building it, because the first working version was quietly doing something we spend a lot of words telling other people not to do. Why MISP, and how we found out We ship STIX 2.1, TAXII 2.1, CSV blocklists and native OP
Patrick Duggan
Aug 155 min read
bottom of page