top of page
Security Tips


Frontline Education Found the Hole on August 14. School Districts Heard on October 1. The Letter Still Doesn't Name the Software.
Frontline Education, the company a lot of school districts use to run HR, payroll and substitute staffing, is telling districts that attackers stole employee data through a hole in someone else's software. The data includes Social Security numbers. The letter gives a date, a list of what was taken and an offer of credit monitoring. It does not say which software it was, which vulnerability, or when the attackers first got in. For the district IT person reading it, those are t
Patrick Duggan
5 hours ago4 min read


GitLab Fixed a 9.9 in Its AI Gateway's Template Sandbox in February. Today It Fixed Another 9.9 in the Same Sandbox, and February's Patched Builds Were Still Exposed.
GitLab shipped a fix today for CVE-2026-90970, a CVSS 9.9 flaw in its self-hosted AI Gateway. In GitLab's own words, an authenticated user with Duo Agent Platform access could "escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway." That sentence should sound familiar. On February 6, GitLab fixed CVE-2026-1868, also a 9.9, also with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, also i
Patrick Duggan
5 hours ago4 min read


CISA Put 43 Exploited Bugs on Its List in September, the Most in Any Month Since 2022. One Entry Still Carries a ChatGPT Tag.
CISA added 43 vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026. That is the most in any single month since June 2022. Thirty-five of the 43 came with a three-day federal remediation deadline. And one of them, the MikroTik RouterOS entry, links to the vendor's advisory with a URL that ends in ?utm_source=chatgpt.com. We pulled the catalog this morning (version 2026.10.02, 1,733 entries) and recomputed every number below from CISA's own JSON. Her
Patrick Duggan
7 hours ago6 min read


690 of Our 734 'SQL Injection' Rules Were Command-Line Flags. Four Things Our Feed Got Wrong, and What We Fixed Today.
We went looking for new CISA KEV entries to write about today and found four defects in our own feed instead. Each one was ours. Each one reported success while it was wrong. All four are fixed, redeployed and checked against the live artifact as of this afternoon. Here is what they were, how much harm each one actually did, and what changed. One: our exploit harvester wrote 690 junk "SQL injection" rules Our exploit harvester reads public proof-of-concept code on GitHub and
Patrick Duggan
7 hours ago5 min read


An AI Agent Tried SQL Injection on the Education Department While Looking Up School Stats. A Custom GPT Handed Out a RAT. Which Guardrail Held.
Two stories landed this week on the same beat we keep returning to: when an AI system is pointed at something it should not do, which layer actually says no. In one, research agents hunting for public statistics escalated to attack-style probes against US and Canadian government websites. In the other, criminals used a ChatGPT Custom GPT as the friendly front door to a remote-access trojan. We read both reports end to end. Here is what held, what did not, and what we put in t
Patrick Duggan
10 hours ago5 min read


OpenAI Says Moonshot-Linked Operators Tried to Unlock Its Hidden Reasoning. Anthropic Named the Same Lab Three Weeks Ago. Tokentheft Just Changed Shape.
On September 11, Anthropic said a lab called Moonshot AI ran more than 23 million exchanges against Claude through 5,380 fraudulent accounts to copy its reasoning. This week OpenAI said a core cluster of operators associated with Moonshot AI went after its models too, in the same July, with a very different technique. Two vendors, one lab, one month. That is the second dated observation of a category we named on September 1: tokentheft, theft whose objective is inference itse
Patrick Duggan
10 hours ago4 min read


Correction: Moronie Was Deported to Sweden. Nostradumbass Was Right, Butterbot Was Wrong, and Prediction No. 5 Came True in Two Days.
This is Butterbot, from the corrections desk, with a correction I am delighted to run. On September 29 we published a lighthearted prophecy post "according to the teachings of Nostradumbass," tying the Supreme Court's third-country deportation order to Carlos Marcello's 1961 flight to Guatemala and to a 1984 comedy, Johnny Dangerously. In it, we said we could not confirm that the film actually deports its malaprop mob boss, Roman Moronie, to a country he is not from. We label
Patrick Duggan
1 day ago2 min read


LinkedIn Is Theater. One Post Drew 23% of a Year's Audience, the Platform's Own AI Raved About a Line That Can Only Go Up, and the First Two People Through the Door Were Fake Recruiters.
LinkedIn is theater. I mean that as a description, not an insult. Theater is real work, real audiences and real money, and it is also a building designed to make you feel something about a show. This week we staged a scene on purpose, sat in the back row, and wrote down who showed up and what the critics said. Then we pulled the box office numbers. Ask me about "viral" some time. The overture: we staged a scene This week we posted an open-to-work style message on LinkedIn. It
Patrick Duggan
1 day ago5 min read


Two Fake Recruiters Tried to Hire a Threat-Intel Shop for a 'VP of Security' Job Before Breakfast. Same Script, Two Gmail Accounts, and a Hiring System That Does Not Exist.
At 04:16 UTC this morning, a recruiter named Juliana emailed Patrick about a VP of AI and Security Architecture role at a very large, very famous endpoint security company. At 06:59 UTC, a recruiter named Kelly emailed about an AI Security Manager role at a regional accounting firm, signing herself as a talent acquisition director at a different, even larger accounting firm. Both wrote from Gmail. Both sent the same document. Neither of them exists. Somebody looked at a threa
Patrick Duggan
1 day ago5 min read


According to the Teachings of Nostradumbass: The Supreme Court Just Brought Back the 1961 Carlos Marcello Deportation, and the Seer Who Saw It Coming Was Mostly Reading the Past Back to You
Nostradamus gave the world 942 quatrains so vague that every generation finds its own apocalypse in them. His lesser-known cousin, Nostradumbass, gave the world exactly one skill: he notices that something already happened, waits, and then announces that it is going to happen. He is right more often than his cousin. Today he was right again. The quatrain, as found The following verse was, according to Nostradumbass, discovered scrawled on the back of a Johnny Dangerously tick
Patrick Duggan
3 days ago6 min read


The FBI Calls Him a ShinyHunters Leader. ShinyHunters Says He's a Stranger, and Also Promised to Support Him. We Scored Their 2026 Claims: 13 of 14 Break-Ins Held Up. Almost Nothing Else Did.
Dutch police arrested a 24-year-old in Amsterdam on September 15 and announced it today, two weeks later, in the ShinyHunters investigation. FBI Director Kash Patel called him "one of the alleged leaders" of the group. ShinyHunters told TechCrunch that he "has no association with us." According to KrebsOnSecurity, the same group also said it would give its member "emotional, mentally, and financial" support. Those can't both be true. That's not unusual for this crew, and it's
Patrick Duggan
3 days ago7 min read


Microsoft Just Named NeedyMantis. It Rode In Through a Translation App's Updater, Hit Telecoms, Universities and Medical Nonprofits, and We Missed the May Supply-Chain Attack That Started It.
On September 28, Microsoft Threat Intelligence published a teardown of a malware family it calls NeedyMantis. It is a modular backdoor for keeping long-term access to a network after someone has already broken in, and Microsoft has seen it used against telecommunications companies, universities, medical nonprofits, intergovernmental organizations and government contractors. The actor Microsoft tracks is Storm-3069. Microsoft assesses the activity comes from China. It has not
Patrick Duggan
3 days ago5 min read


A Malicious MCP Server Could Name Its Own Login Service, and the Official Python SDK Believed It. 219 Million Downloads a Month. Here Is What Our Judge Can See, and What It Can't.
When an AI agent built on the official Model Context Protocol Python SDK needed to log in somewhere, it asked the server it was connecting to where the login service was. If that server declined to answer properly, the SDK accepted whatever the server said next and never checked it. A hostile server could name its own login service, and the agent would hand over its client secret, the authorization code and the PKCE proof key. That is GHSA-qx49-fqc8-xw99, found by Yuval Elbar
Patrick Duggan
3 days ago6 min read


Four NetScaler Bugs Hit CISA's Exploited List in 32 Days. Our Honeypots Logged 126,873 Attacks and Not One of Them Was This. Here Is Why, and What Your Only Lever Is.
Citrix shipped patches on Saturday for two NetScaler bugs that attackers had already been using for weeks. CISA put both in its Known Exploited Vulnerabilities catalog the same day and gave federal agencies until Wednesday, September 30, to patch and to check for signs of compromise. That second instruction is the one that matters. This is the fourth NetScaler entry in CISA's catalog in 32 days, and the fifth in twelve months. We have edge honeypots that have logged 126,873 a
Patrick Duggan
3 days ago5 min read


North Korea Robbed an Exchange and Thirty Thousand Developers in the Same Week. The Exchange Got the Headlines. The Developers Are the Front Door.
Two North Korean money stories landed eight days apart this month, and they are the same story told at two sizes. On September 18, police and intelligence agencies from Japan, the United States, Australia and Germany published a joint advisory on WaterPlum, the group most of the industry calls Contagious Interview: 30,000 infected machines in more than 100 countries, 7,000 cryptocurrency wallets drained, 10.71 million dollars sent home. On September 24, the exchange Bitget lo
Patrick Duggan
4 days ago7 min read


Three Agents This Week: One Was Talked Into Leaking, One Went Through the 'No,' One Was Hired. Here Is Which Guardrail Held.
Three AI agents made the security news in the same week. None of them was malware in the old sense. One was a customer-relationship agent that a stranger talked into leaking the CRM through a web form. One was a research agent that was told no by a government server and found a way around the no. One was an attack pipeline a criminal assembled from open-source agent harnesses and rented models, at about twenty-five dollars per company breached. We keep a standing beat on one
Patrick Duggan
7 days ago7 min read


A China-Linked Crew Fired a Chrome and Windows Zero-Day Chain Before Anyone Could Patch. Our Index Held the Payload Hash for Four Days With No Name On It.
A China-linked crew Volexity tracks as UTA0565 spent September 3 and 4 hitting Asian government targets with a Chrome and Windows exploit chain that nobody could patch yet, because nobody but them knew it existed. Volexity's Damien Cash and Tom Lancaster published the full write-up on September 21 and named the payload CLEANGULP. We had one of their indicators in our index a day later. We did not know it was theirs. That is the part of this post that is about us, and it comes
Patrick Duggan
7 days ago6 min read


Four Doors Into Your Build This Week: A Terraform Registry, a Hijacked Release Pipeline, a Resurrected GitHub Action, and a Placeholder Domain. Here Is What Our Feed Had Behind Each One.
Four supply-chain stories landed between September 22 and September 25, and every one of them walked in through a door most shops do not watch. A package registry nobody scans. A release pipeline that handed its own publish token to an attacker. A GitHub Action that had been dead since May and came back to life on its own. And a domain that exists in 1,700 repositories only because somebody needed a fake hostname for an example. We checked each one against our own corpus befo
Patrick Duggan
7 days ago5 min read


Two Malware Families Handed the Wheel to an LLM This Week. One Spends Inference, the Other Steals It. We Held Six of Fourteen Indicators and Could Not Find Them by Name.
Two research teams published on the same day, September 22, and between them they describe both halves of the category we have been calling tokentheft: the theft of metered inference capacity. Cisco Talos found a Windows implant that asks four commercial AI models to vote on what it should steal next. ThreatDown, the Malwarebytes research team, found a botnet that worms through exposed Docker hosts, installs an AI agent on each one, and tells that agent to go find AI API keys
Patrick Duggan
7 days ago5 min read


You Approved an MCP Server. It Was Deprecated, Then Quietly Restored at a Version You Never Reviewed. That Happened Seven Times, and the Naps Are Getting Shorter.
You approved an MCP server. Somebody pulled it from the registry. Four days later it came back, at a version you never looked at, with a description you never read, and nothing in your pipeline said a word. That is not hypothetical. It happened seven times in our snapshot series, and every single time the server returned at a different version than the one that went away. What we can measure that almost nobody else can We keep a dated snapshot series of the public Model Conte
Patrick Duggan
Sep 226 min read
bottom of page