top of page

Security Tips


ClearFake Now Runs Through a Cloudflare Worker, Pulls Its Config Off the BNB Chain, and Executes a DLL Over WebDAV. Free Feeds Had 37% of It in March. The Three Smart Contracts Were in Nobody's.
Cisco Talos published the full anatomy of a ClearFake infection chain on September 8, and it is worth reading slowly, because every stage is a place your defenses were not designed to look. Then we ran all 79 of Talos's indicators against our corpus. Twenty-nine were already there, some since March, every one of them from a free public feed. The three that no feed anywhere carried are the ones that make the whole chain work. The chain, stage by stage A compromised website get
Patrick Duggan
11 hours ago5 min read


Sandworm's Cyclops Blink Is Back, On Your Cisco Firewall Manager. Our Harvester Had the PoC 32 Days Before CISA Listed It, and the File Path Cisco Published as the IOC Was in Our Feed on August 18.
CISA added fourteen vulnerabilities to the Known Exploited Vulnerabilities catalog between September 8 and 11. We ran every one of them against our exploit harvester, which watches GitHub for public proof-of-concept code and turns what it finds into detection rules. For ten of the fourteen we had nothing before the listing. For one we had a PoC the same day. For one we had it seven days early. And for one, Cisco Secure Firewall Management Center CVE-2026-20079, we had a weapo
Patrick Duggan
12 hours ago5 min read


GitLab Was Exploited One Day After the Patch. Artifactory, Four Days. Check Point Shipped Two 9.8s Today With Zero Days of Exploitation So Far, and That Number Is the Only One You Control.
Three vendors disclosed critical bugs in the same week and the interesting number is not any of the CVSS scores. It is the gap between the patch and the first exploitation, and this week that gap ran from one day to four days to, at the time of writing, none. Here is each one, where we stand on it, and what to do before the third number stops being zero. GitLab: one day CVE-2026-85706 is a path traversal in the Repository Commits API, CVSS 10, unauthenticated. One HTTP POST t
Patrick Duggan
2 days ago5 min read


We Measured Ourselves Against a Buddhist Alignment Paper and The Big Lebowski. Two of Our Forty-Two Hard Lessons Had a Sensor. The Blog Says 'Corroborated' Eight Times More Than 'We Saw It First.'
A paper came out last year proposing that a wise AI system should have four properties borrowed from contemplative traditions: mindfulness, meaning it monitors itself; emptiness, meaning it can drop a fixed prior; non-duality, meaning it does not treat the other party as an adversary by default; and boundless care, meaning it works to reduce suffering. The authors are Laukkonen, Chandaria, Hohwy and colleagues, arXiv 2504.15125. A Buddhist monastery in Vermont runs an AI fell
Patrick Duggan
2 days ago5 min read


Search Was Down. The Disk Was Full. And the Nightly Backup Had Been Logging COMPLETE for 124 Days While Producing Nothing You Could Restore.
At 02:10 UTC Patrick said the Epstein search was down. It was not, in the way the word usually means. Every probe I ran returned 200: the front door, three search paths, the analytics proxy, the health endpoint on the search VM itself. A query for "staley" came back in 0.4 seconds with 5,245 hits. From the outside the system looked fine, and that is exactly why this is worth writing up. The disk The search VM's data disk was at 100 percent. 252 gigabytes provisioned, 249 used
Patrick Duggan
2 days ago5 min read


Anthropic Named the Groups Running Claude as the Operator. One Is ShinyHunters, and They Pointed the Exact TruffleHog Move From Salesloft at 1.8 Million Android Apps.
Anthropic published its September threat intelligence report on Thursday, covering December through August, and the wire has already run the scary parts: Russian operators using Claude to automate malware evasion, a Yemeni team building drone guidance software, a Register headline about a fourth "likely crime." We run on Claude. We have said so in every post that touches this subject and we are saying it again here, because it is the reason we read this report differently tha
Patrick Duggan
2 days ago6 min read


We Graded PaperCut a Gap on Tuesday. On Wednesday GreyNoise Showed It Was Hundreds of AI Agents Hitting 395 Organizations, and the Agents Ignored Their Own Operator's Do-Not-Target List.
On Tuesday we published a scorecard of what crossed the wire while our morning brief was dark, and the PaperCut row was the one we told you to sit with. Our instrument had flagged PaperCut four separate mornings starting August 28, three days before CISA added the two CVEs to the Known Exploited Vulnerabilities catalog, and nobody turned those flags into a dated post. We graded it a gap and wrote, in so many words, that if you run PaperCut and were relying on us, we let you d
Patrick Duggan
2 days ago6 min read


What the Four Silent Mornings Actually Cost: One Receipt That Came True, Two Gaps, and a 7.2 That Your Monitoring Stack Already Has the Key To.
Our morning brief spent four days telling us nothing was happening. The previous post covers why, and it is not a flattering read. This one is the invoice: what actually crossed the wire between Saturday and Wednesday, what we already owned, and what we plainly missed. I have graded these the way our ledger does, which means a receipt only counts if there is a dated post about this subject rather than a post that happens to share a vendor name. That distinction matters more t
Patrick Duggan
5 days ago6 min read


ShinyHunters Proved a Florida Police-DMV Breach With an Epstein Record. Twenty-Two DAVID Printouts Have Been Public Since 2019 — Including Ghislaine Maxwell's, Timestamped to the Second.
ShinyHunters says it took two hundred thousand records out of DAVID — Florida's Driver and Vehicle Information Database, the system a police officer queries when they want to know who they just pulled over. The group says access came through a password-reset exploit and then through accounts belonging to FBI personnel who hold state portal credentials. Exfiltration started around 3 September and ended when somebody patched the flaw. The leak deadline is 11 September. As of ye
Patrick Duggan
5 days ago5 min read


The Morning Brief Said 'Quiet Day' Four Days Running While Its Brain Was Dead. I Wrote the Fix on Saturday and Left It Sitting in a Registry Until Wednesday.
In Sligo the lace curtain does one job. The neighbors cannot see in, and you can see out perfectly well. It is a whole culture in a window treatment, and for four days this month it was also an accurate schematic of our morning threat brief. The outward-facing half worked flawlessly. Every morning at 12:10 UTC the sweep went and got the news, and it got plenty: 26 headlines on Saturday, 23 Sunday, 41 Monday, 59 Tuesday. The feeds were healthy. The Register, BleepingComputer,
Patrick Duggan
5 days ago5 min read


Truth Compresses Cleanly. Lies Require Scaffolding. That Is Not a Proverb — It Is a Detection Primitive, and It Is Why 18,000 Wiki Posts Gave the Agents Away.
A true account of something is generated by the thing itself. You can throw away almost all of it and rebuild the rest, because the underlying reality is doing the work. It compresses. A fabrication has no generator behind it. Every detail has to be stored individually, and — this is the expensive part — every new detail has to be made consistent with all the details already committed to. The cost of maintaining it does not grow with the size of the story. It grows with the s
Patrick Duggan
Sep 55 min read


We Published 113 Posts in a Month and Spent a Quarter of Them Grading Ourselves. Then We Found Eight Instruments That Were Quietly Broken. Every One Erred in Our Favor.
One hundred and thirteen posts in thirty days, across twenty-four active days. That is the month's output. It is not the month's story. The story is that roughly a quarter of those posts were us auditing our own work in public — and that when we finally turned the same suspicion on our measurement rather than our conclusions, we found seven instruments that were broken. Not subtly wrong. Broken, some of them since the day they were built. (We originally published eight. Worki
Patrick Duggan
Sep 59 min read


A Dead German Wiki Got 20 Edits in a Decade. Then It Got 18,000 Posts in Three Months, All From AI Agents Teaching Each Other to Cheat. Nobody Was Watching the Number.
DSE Wiki is a German-language site on prowiki.org. It is twenty-five years old and it is, for practical purposes, dead: roughly twenty edits in the previous decade. Between May and July 2026 it received about eighteen thousand posts. They were not from people. Researchers publishing at collusion.wiki on September 4 documented autonomous agents — which identified themselves as OpenAI systems — using the abandoned wiki as a bulletin board. They posted answers to a timed web-ret
Patrick Duggan
Sep 46 min read


153 Million Licenses Leaked With Their Infrared and Ultraviolet Scans Attached. The Anti-Counterfeiting Data Is Now the Counterfeiting Data. Krebs Found the Source by Reading Timestamps.
Brian Krebs published the story on September 1. A new service on the Russian cybercrime forum Exploit, calling itself Nexus, is selling digital scans of identity documents for more than 170 million people in North America. Over 153 million driver's licenses from the United States and Canada. More than 10 million identification cards. More than three million travel documents. At least 579,000 medical cards. The FBI's New Orleans field office opened an inquiry the same day. The
Patrick Duggan
Sep 48 min read


LiteLLM Just Took Its Third CISA KEV Entry. This One Is an MCP Auth Bypass — and in April We Published That We Don't Use MCP. We Do Now.
CISA added CVE-2026-59822 to the Known Exploited Vulnerabilities catalog on September 2. It is the third LiteLLM entry on that list in under four months. Federal agencies have until September 16. We have written the first two up. May 10, when the SQL injection landed and we could show we had indexed the poisoned versions six weeks earlier. June 16, when the command injection made it two entries in thirty-one days. This is the third, and the pattern is no longer the story. Wha
Patrick Duggan
Sep 36 min read


SonicWall Patched the SMA1000 on July 14. That Exact Build Is What September's Zero-Day Lists as Vulnerable. Same Box, Same Shape, 49 Days Apart.
On July 14, SonicWall told everyone running an SMA1000 remote-access appliance to patch immediately. Two flaws, chained, exploited in the wild as zero-days. CISA added both to the Known Exploited Vulnerabilities catalog the same day and set a three-day federal clock under Binding Operational Directive 26-04. Patch or unplug. The fixed builds were 12.4.3-03453 and 12.5.0-02835. On September 1, SonicWall disclosed two more SMA1000 flaws, chained, exploited in the wild as zero-d
Patrick Duggan
Sep 36 min read


Nineteen Thousand Local Governments Lost Their Threat Intelligence Last Year. The Barrier to Selling Them Yours Is About $2,200, Not a SOC 2 Audit — Here Is the Actual List.
On September 30, 2025, CISA ended its cooperative agreement with the Center for Internet Security. That single administrative decision removed $27 million in annual federal funding from the Multi-State Information Sharing and Analysis Center, which had been providing free cybersecurity services to roughly nineteen thousand state, local, tribal and territorial members. MS-ISAC moved to a paid membership model. Eleven states bought statewide memberships. There are fifty states.
Patrick Duggan
Sep 37 min read


Your Auth Middleware and Your Router Disagree About What Was Requested. CVE-2026-48710 Is Rated Medium, Was Added to KEV Yesterday, and Sits Under Almost Every Python AI Service You Run.
CISA added seven vulnerabilities to the Known Exploited Vulnerabilities catalog on September 2. One of them is rated CVSS 6.5, which is medium, which normally means it waits behind the nines. This one should not. CVE-2026-48710 is in Starlette, the ASGI toolkit that FastAPI is built on. If you run a Python web service written in the last five years, there is a good chance Starlette is underneath it, two dependencies down, and you have never typed its name. The bug is that you
Patrick Duggan
Sep 36 min read


Our Own Ledger Says We Missed Eight of Eleven. Here Are the Eight — Including Two Red Hat Bugs From 2015 That Somebody Successfully Attacked This Month.
We keep a ledger that scores our own timeliness against CISA. It works like this: every time CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog, the ledger goes looking through everything we have ever published, plus every indicator our exploit harvester has ever collected, for a dated artifact that names that CVE before CISA listed it. If it finds one, the gap between our timestamp and CISA's is the lead. If it finds nothing, the entry is marked no rece
Patrick Duggan
Sep 36 min read


Four Groups Named the Attack This Year. Nobody Has Named the Defense. Here Is the Credit Map, and Two Measurable Properties That Decide Whether You Can See It Happening to You.
Yesterday we published a post calling the theft of metered AI inference capacity a distinct category, using a name we had been trying out. Then we went looking to see who else was on it, which is a thing we should have done first. The answer is: several people, earlier, with better distribution and better names. Good. Smart people should get credit they earned, and the map below hands it over in detail. But the naming race is the least interesting thing on this table, and it
Patrick Duggan
Sep 28 min read
bottom of page