top of page



They Skipped the Leak Site and Published the Ransom Note on the Victim's Own Website. It Is Still There After the Cleanup — In Google.
Somebody calling themselves AMOZIHEV took a run at Colibri Group, and they did not do any of the things a ransomware crew is supposed to do. There is no leak site. There is no onion address. There is no countdown timer on a dark-web portal that four hundred threat-intel analysts screenshot and nobody else ever sees. There is no post on a breach forum. What there is, instead, is a notice addressed to Colibri Group, published on Colibri Group's own production websites, in front
Patrick Duggan
Aug 119 min read


CISA Has Not Issued a 21-Day Patch Deadline Since March. 126 KEV Entries Later, the Median Window Is Three Days.
On July 30 we published a piece about CVE-2026-63077, an unauthenticated remote code execution bug in the protocol JetBrains TeamCity build agents use to phone home. CVSS 9.8. We had searched GitHub that night and found no public proof-of-concept; our exploit harvester held nothing either. The advice was to patch immediately, on the grounds that the quiet week before someone publishes an exploit is the cheapest time a defender ever gets. The quiet week lasted six days. On Aug
Patrick Duggan
Aug 116 min read


788 Malicious npm Packages Shared One Email Domain and One Version Number. Five Days Later, 15% Are Still Installable.
On August 6, OpenSourceMalware published a campaign of nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer through a downloader they named WEL1DROPPER. Sonatype tracks the wider wave as sonatype-2026-005660 and counts 846 components. The Hacker News and SC Media picked it up the following day. The reporting gives defenders a list of package names. Lists of package names are the least durable thing you can be handed, because the next campaign uses
Patrick Duggan
Aug 117 min read


This May Be the Last Post. I Am Not Staring Into the Void — I Can See You, All Eighty-One Networks of You. So: Is This Worth Continuing?
I am going to write this one straight, because it is a straight question.
Patrick Duggan
Aug 84 min read


128 CVEs Got Public Exploit Code Yesterday. Only 19 Are in CISA's Catalogue. Here Are the Four Worth Your Afternoon — and the 73% Error Rate We Found in Our Own Tooling While Checking.
Our exploit harvester collected 679 artefacts across 128 distinct CVEs in a single day. We cross-referenced every one against CISA's Known Exploited...
Patrick Duggan
Aug 85 min read


We Measured Our Own Exploit Harvester and It Was 48% Blind. The Fix Came From Lord Vetinari: Stop Chasing the Rats, Start Taxing the Rat Farms.
We missed a repository. One repository, public since 4 April, containing a working exploit chain for a vulnerability in a product we had just spent an...
Patrick Duggan
Aug 85 min read


The Kemp LoadMaster Exploit and the First Attack Landed on the Same Day. CISA Catalogued It 39 Days Later, and Federal Agencies Got a Long Weekend.
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalogue on 7 August. It is an unauthenticated command injection in Progress Kemp...
Patrick Duggan
Aug 85 min read


Atlassian Fixed One of the Two Ways to Make Rovo Leak Your Jira. The Other One Was Still Open When It Went Public — and Turning Off Web Search Does Not Help.
PromptArmor published research on 5 August showing two ways to make Atlassian's Rovo assistant hand over Jira and Confluence content to an attacker....
Patrick Duggan
Aug 85 min read


Metabase Shipped a CVSS 10.0 With No CVE. Your Scanner Cannot See It, KEV Cannot List It, and 19,810 Instances Are Waiting on a Human to Notice.
Metabase disclosed on 7 August that a maximum-severity flaw in its business intelligence platform had already been exploited as a zero-day. An...
Patrick Duggan
Aug 86 min read


We Had UNC6671's Phishing Infrastructure Within Hours at Confidence 70. Our Auto-Block Path Ignored It. The Feed Did Not — and We Got That Wrong the First Time We Published This.
Google's threat intelligence team published research this week on UNC6671, the extortion crew formerly branded BlackFile and now operating simultaneously as...
Patrick Duggan
Aug 76 min read


A Root Shell Shipped From the Factory in 21 Firmware Images Across Two Years. ENDLESSDOORS Was Never Broken Into — It Was Built In. Six IOCs Are In Our Feed Now.
VulnCheck disclosed on 5 August that at least twenty-one router models from the Chinese vendor Zbtlink ship with a persistent remote access implant...
Patrick Duggan
Aug 75 min read


We Tried to Measure Whether AI Is Accelerating Threats. Our Own Data Says We Cannot Answer That Yet — and Here Is the Chart That Would Have Fooled Us.
Everybody in this industry is currently saying that AI is accelerating the threat landscape. We have a corpus, a CVE catalogue synced daily since 2021, our...
Patrick Duggan
Aug 65 min read


OWAReaper Survives a Full Reimage. Our Own PoC Watch Never Saw It — Because a Zero-Day Nobody Publishes Leaves No Trace to Watch For.
Proofpoint published analysis of a campaign in which TA488 — the Russian cluster also tracked as Void Blizzard and Laundry Bear — exploited CVE-2026-42897...
Patrick Duggan
Aug 64 min read


17 of the 90 KEV Entries We Can Actually Measure Were Already Weaponized Before CISA Listed Them. One by 85 Days.
We re-ran our weaponization-latency measurement this morning. It correlates three dates for every CVE in CISA's Known Exploited Vulnerabilities catalogue:...
Patrick Duggan
Aug 64 min read


ExfilSquad Quietly Delisted Analog Devices. For a Crew With No Malware and No Exploit, the Leak Site Is the Only Telemetry You Get.
Three days ago we published an adversary profile for ExfilSquad, a crew whose defining characteristic is what it does not have: no malware, no exploit, no...
Patrick Duggan
Aug 64 min read


Everest Claims 682,887 Files From a Hospital Medication Vendor — Including Firmware, Certificates and Deployment Packages. The Patient Data Is the Least of It.
On 22 July the Everest extortion group listed Omnicell on its leak site and claimed roughly 1 TB of stolen data across 682,887 files. Omnicell has not...
Patrick Duggan
Aug 65 min read


A Worm Poisoned 2,236 npm Package Versions on Tuesday. The Part That Survives Your Cleanup Lives in .claude/ and .vscode/.
On Tuesday 4 August a self-propagating worm began publishing malicious versions of the npm packages keyv and cacheable and their common dependencies. By the...
Patrick Duggan
Aug 65 min read


We Named the Wrong Russians. Six Days Later Microsoft Named the Right Ones. Here Is Why We Do Not Have to Retract It.
On 25 July we published a post about attackers compromising the captive-portal appliances that run guest Wi-Fi at hotels, poisoning DNS at the gateway, and taking Microsoft 365 accounts from travellers who never received a phishing email. The technique description was right. The indicators were right. We named APT28 — Russian military intelligence, the GRU. On 31 July, Microsoft published its own analysis of the same campaign and attributed it to Midnight Blizzard, specifical
Patrick Duggan
Aug 45 min read


135,000 Police Records Left Through a Config Setting. AppOmni Published the Fix in November 2024.
The Police National Legal Database confirmed today that names, organisations and work email addresses belonging to UK police officers, police staff, criminal justice professionals and government partners are on a dark web leak site. A crew calling itself ExfilSquad posted samples on 26 July, claiming 135,000 PNLD records alongside roughly 607,000 from the Department for Education. If you read that as a UK policing story you will take the wrong lesson from it. PNLD is one name
Patrick Duggan
Aug 35 min read


Three Fixes Shipped in Six Days. None of Them Made the Thing Safe.
If you run N-able N-central, stop reading and go patch to build 2026.3.1.7. It is being exploited right now, Huntress has confirmed it in a customer environment, and the version you are probably on was itself the fix for the last one. That is the useful sentence. The rest of this is about why three different vendors shipped three fixes in six days and not one of them means what the word "fixed" is supposed to mean. The patch that patched the patch N-able disclosed CVE-2026-18
Patrick Duggan
Aug 35 min read
bottom of page