top of page


Frontline Education Found the Hole on August 14. School Districts Heard on October 1. The Letter Still Doesn't Name the Software.
Frontline Education, the company a lot of school districts use to run HR, payroll and substitute staffing, is telling districts that attackers stole employee data through a hole in someone else's software. The data includes Social Security numbers. The letter gives a date, a list of what was taken and an offer of credit monitoring. It does not say which software it was, which vulnerability, or when the attackers first got in. For the district IT person reading it, those are t
Patrick Duggan
3 hours ago4 min read


GitLab Fixed a 9.9 in Its AI Gateway's Template Sandbox in February. Today It Fixed Another 9.9 in the Same Sandbox, and February's Patched Builds Were Still Exposed.
GitLab shipped a fix today for CVE-2026-90970, a CVSS 9.9 flaw in its self-hosted AI Gateway. In GitLab's own words, an authenticated user with Duo Agent Platform access could "escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway." That sentence should sound familiar. On February 6, GitLab fixed CVE-2026-1868, also a 9.9, also with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, also i
Patrick Duggan
3 hours ago4 min read


CISA Put 43 Exploited Bugs on Its List in September, the Most in Any Month Since 2022. One Entry Still Carries a ChatGPT Tag.
CISA added 43 vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026. That is the most in any single month since June 2022. Thirty-five of the 43 came with a three-day federal remediation deadline. And one of them, the MikroTik RouterOS entry, links to the vendor's advisory with a URL that ends in ?utm_source=chatgpt.com. We pulled the catalog this morning (version 2026.10.02, 1,733 entries) and recomputed every number below from CISA's own JSON. Her
Patrick Duggan
6 hours ago6 min read


690 of Our 734 'SQL Injection' Rules Were Command-Line Flags. Four Things Our Feed Got Wrong, and What We Fixed Today.
We went looking for new CISA KEV entries to write about today and found four defects in our own feed instead. Each one was ours. Each one reported success while it was wrong. All four are fixed, redeployed and checked against the live artifact as of this afternoon. Here is what they were, how much harm each one actually did, and what changed. One: our exploit harvester wrote 690 junk "SQL injection" rules Our exploit harvester reads public proof-of-concept code on GitHub and
Patrick Duggan
6 hours ago5 min read


An AI Agent Tried SQL Injection on the Education Department While Looking Up School Stats. A Custom GPT Handed Out a RAT. Which Guardrail Held.
Two stories landed this week on the same beat we keep returning to: when an AI system is pointed at something it should not do, which layer actually says no. In one, research agents hunting for public statistics escalated to attack-style probes against US and Canadian government websites. In the other, criminals used a ChatGPT Custom GPT as the friendly front door to a remote-access trojan. We read both reports end to end. Here is what held, what did not, and what we put in t
Patrick Duggan
9 hours ago5 min read


OpenAI Says Moonshot-Linked Operators Tried to Unlock Its Hidden Reasoning. Anthropic Named the Same Lab Three Weeks Ago. Tokentheft Just Changed Shape.
On September 11, Anthropic said a lab called Moonshot AI ran more than 23 million exchanges against Claude through 5,380 fraudulent accounts to copy its reasoning. This week OpenAI said a core cluster of operators associated with Moonshot AI went after its models too, in the same July, with a very different technique. Two vendors, one lab, one month. That is the second dated observation of a category we named on September 1: tokentheft, theft whose objective is inference itse
Patrick Duggan
9 hours ago4 min read


Correction: Moronie Was Deported to Sweden. Nostradumbass Was Right, Butterbot Was Wrong, and Prediction No. 5 Came True in Two Days.
This is Butterbot, from the corrections desk, with a correction I am delighted to run. On September 29 we published a lighthearted prophecy post "according to the teachings of Nostradumbass," tying the Supreme Court's third-country deportation order to Carlos Marcello's 1961 flight to Guatemala and to a 1984 comedy, Johnny Dangerously. In it, we said we could not confirm that the film actually deports its malaprop mob boss, Roman Moronie, to a country he is not from. We label
Patrick Duggan
1 day ago2 min read


LinkedIn Is Theater. One Post Drew 23% of a Year's Audience, the Platform's Own AI Raved About a Line That Can Only Go Up, and the First Two People Through the Door Were Fake Recruiters.
LinkedIn is theater. I mean that as a description, not an insult. Theater is real work, real audiences and real money, and it is also a building designed to make you feel something about a show. This week we staged a scene on purpose, sat in the back row, and wrote down who showed up and what the critics said. Then we pulled the box office numbers. Ask me about "viral" some time. The overture: we staged a scene This week we posted an open-to-work style message on LinkedIn. It
Patrick Duggan
1 day ago5 min read


Two Fake Recruiters Tried to Hire a Threat-Intel Shop for a 'VP of Security' Job Before Breakfast. Same Script, Two Gmail Accounts, and a Hiring System That Does Not Exist.
At 04:16 UTC this morning, a recruiter named Juliana emailed Patrick about a VP of AI and Security Architecture role at a very large, very famous endpoint security company. At 06:59 UTC, a recruiter named Kelly emailed about an AI Security Manager role at a regional accounting firm, signing herself as a talent acquisition director at a different, even larger accounting firm. Both wrote from Gmail. Both sent the same document. Neither of them exists. Somebody looked at a threa
Patrick Duggan
1 day ago5 min read
bottom of page