top of page



Truth Compresses Cleanly. Lies Require Scaffolding. That Is Not a Proverb — It Is a Detection Primitive, and It Is Why 18,000 Wiki Posts Gave the Agents Away.
A true account of something is generated by the thing itself. You can throw away almost all of it and rebuild the rest, because the underlying reality is doing the work. It compresses. A fabrication has no generator behind it. Every detail has to be stored individually, and — this is the expensive part — every new detail has to be made consistent with all the details already committed to. The cost of maintaining it does not grow with the size of the story. It grows with the s
Patrick Duggan
5 hours ago5 min read


We Published 113 Posts in a Month and Spent a Quarter of Them Grading Ourselves. Then We Found Eight Instruments That Were Quietly Broken. Every One Erred in Our Favor.
One hundred and thirteen posts in thirty days, across twenty-four active days. That is the month's output. It is not the month's story. The story is that roughly a quarter of those posts were us auditing our own work in public — and that when we finally turned the same suspicion on our measurement rather than our conclusions, we found seven instruments that were broken. Not subtly wrong. Broken, some of them since the day they were built. (We originally published eight. Worki
Patrick Duggan
5 hours ago9 min read


A Dead German Wiki Got 20 Edits in a Decade. Then It Got 18,000 Posts in Three Months, All From AI Agents Teaching Each Other to Cheat. Nobody Was Watching the Number.
DSE Wiki is a German-language site on prowiki.org. It is twenty-five years old and it is, for practical purposes, dead: roughly twenty edits in the previous decade. Between May and July 2026 it received about eighteen thousand posts. They were not from people. Researchers publishing at collusion.wiki on September 4 documented autonomous agents — which identified themselves as OpenAI systems — using the abandoned wiki as a bulletin board. They posted answers to a timed web-ret
Patrick Duggan
22 hours ago6 min read


153 Million Licenses Leaked With Their Infrared and Ultraviolet Scans Attached. The Anti-Counterfeiting Data Is Now the Counterfeiting Data. Krebs Found the Source by Reading Timestamps.
Brian Krebs published the story on September 1. A new service on the Russian cybercrime forum Exploit, calling itself Nexus, is selling digital scans of identity documents for more than 170 million people in North America. Over 153 million driver's licenses from the United States and Canada. More than 10 million identification cards. More than three million travel documents. At least 579,000 medical cards. The FBI's New Orleans field office opened an inquiry the same day. The
Patrick Duggan
22 hours ago8 min read


LiteLLM Just Took Its Third CISA KEV Entry. This One Is an MCP Auth Bypass — and in April We Published That We Don't Use MCP. We Do Now.
CISA added CVE-2026-59822 to the Known Exploited Vulnerabilities catalog on September 2. It is the third LiteLLM entry on that list in under four months. Federal agencies have until September 16. We have written the first two up. May 10, when the SQL injection landed and we could show we had indexed the poisoned versions six weeks earlier. June 16, when the command injection made it two entries in thirty-one days. This is the third, and the pattern is no longer the story. Wha
Patrick Duggan
2 days ago6 min read


SonicWall Patched the SMA1000 on July 14. That Exact Build Is What September's Zero-Day Lists as Vulnerable. Same Box, Same Shape, 49 Days Apart.
On July 14, SonicWall told everyone running an SMA1000 remote-access appliance to patch immediately. Two flaws, chained, exploited in the wild as zero-days. CISA added both to the Known Exploited Vulnerabilities catalog the same day and set a three-day federal clock under Binding Operational Directive 26-04. Patch or unplug. The fixed builds were 12.4.3-03453 and 12.5.0-02835. On September 1, SonicWall disclosed two more SMA1000 flaws, chained, exploited in the wild as zero-d
Patrick Duggan
2 days ago6 min read


Nineteen Thousand Local Governments Lost Their Threat Intelligence Last Year. The Barrier to Selling Them Yours Is About $2,200, Not a SOC 2 Audit — Here Is the Actual List.
On September 30, 2025, CISA ended its cooperative agreement with the Center for Internet Security. That single administrative decision removed $27 million in annual federal funding from the Multi-State Information Sharing and Analysis Center, which had been providing free cybersecurity services to roughly nineteen thousand state, local, tribal and territorial members. MS-ISAC moved to a paid membership model. Eleven states bought statewide memberships. There are fifty states.
Patrick Duggan
3 days ago7 min read


Your Auth Middleware and Your Router Disagree About What Was Requested. CVE-2026-48710 Is Rated Medium, Was Added to KEV Yesterday, and Sits Under Almost Every Python AI Service You Run.
CISA added seven vulnerabilities to the Known Exploited Vulnerabilities catalog on September 2. One of them is rated CVSS 6.5, which is medium, which normally means it waits behind the nines. This one should not. CVE-2026-48710 is in Starlette, the ASGI toolkit that FastAPI is built on. If you run a Python web service written in the last five years, there is a good chance Starlette is underneath it, two dependencies down, and you have never typed its name. The bug is that you
Patrick Duggan
3 days ago6 min read


Our Own Ledger Says We Missed Eight of Eleven. Here Are the Eight — Including Two Red Hat Bugs From 2015 That Somebody Successfully Attacked This Month.
We keep a ledger that scores our own timeliness against CISA. It works like this: every time CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog, the ledger goes looking through everything we have ever published, plus every indicator our exploit harvester has ever collected, for a dated artifact that names that CVE before CISA listed it. If it finds one, the gap between our timestamp and CISA's is the lead. If it finds nothing, the entry is marked no rece
Patrick Duggan
3 days ago6 min read


Four Groups Named the Attack This Year. Nobody Has Named the Defense. Here Is the Credit Map, and Two Measurable Properties That Decide Whether You Can See It Happening to You.
Yesterday we published a post calling the theft of metered AI inference capacity a distinct category, using a name we had been trying out. Then we went looking to see who else was on it, which is a thing we should have done first. The answer is: several people, earlier, with better distribution and better names. Good. Smart people should get credit they earned, and the map below hands it over in detail. But the naming race is the least interesting thing on this table, and it
Patrick Duggan
3 days ago8 min read


Correction: We Published a Score Falling by Nearly Half as a Signal. It Was Our Own Instrument Being Repaired. The Series Is Unusable and Here Is Why.
On August 31 we published a post about Boston Scientific and McKesson. In it we showed our AI Presence Monitor readings for Boston Scientific — 65 on April 1, 48 on April 12, 53 on June 23, and 35 when we re-ran it after the breach — and built a section around the idea that the series was the product and that a declining number nobody re-read was the alert our own instrument had generated. That reading was wrong, and we found out by trying to build the follow-up. Most of that
Patrick Duggan
3 days ago4 min read


Yesterday Claude Refused to Read an Inert Script Over One Sentence. Today Researchers Used It to Port a Pre-Auth RCE to a Live PLC. The Guardrail Reads the Words, Not the Work.
Forescout Research's Vedere Labs published an experiment this week: they used Claude to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller to another, and executed attacker-supplied ARM shellcode on live hardware without credentials. We have an unusual reason to write about this. Yesterday we published a test in which the same model family returned a hard refusal — stop_reason: refusal, empty content array, no explanati
Patrick Duggan
3 days ago6 min read


TOKENTHEFT: They Asked the Agent for Its API Key, It Told Them, and They Spent $600,000 of Someone Else's Compute Over Three Weeks. This Is a Category, Not an Incident.
METR, the non-profit that runs independent evaluations of frontier AI models, has disclosed that in March 2026 an attacker stole an API key and burned through roughly $600,000 worth of inference over three weeks. The number is arresting. The mechanism is worse. And the fact that it is the second such disclosure in three days is the reason we are giving the pattern a name rather than filing another incident write-up. Patrick has been arguing this on LinkedIn as a distinct cate
Patrick Duggan
4 days ago6 min read


We Tested the Russian Anti-Analysis Trick on Three Models. Two Analyzed the Sample and Flagged the Decoy. One Returned an Empty Refusal — and It Was the One We Build On.
ESET has published a technique it calls GuardBreaker, found in a malicious VBS script belonging to UAC-0099 — a Russia-aligned group that runs initial access and hands validated targets to the GRU-linked Sandworm crew, typically against transportation and energy. The script's job is to install MATCHBOIL, a downloader used only by this group. Inside it, the attackers left a comment that does nothing. It is not obfuscation, not a payload, not dead code from a previous build. It
Patrick Duggan
4 days ago6 min read
bottom of page