top of page

All Posts


The DOJ Took 18 Months to Indict a Bulletproof Host. A Defender Blocks One in a Day. Here's the Method — and Why We Keep a Shitlist.
The Justice Department unsealed an indictment this week against three Russian nationals and two companies for running the infrastructure under a big slice of the cybercrime economy. The companies are Media Land LLC and ML.Cloud LLC, both out of St. Petersburg. The people are Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova. The charge sheet — computer-fraud conspiracy, wire fraud, money laundering — covers 42 victims across 21 US states and roughly 62 million dollars
Patrick Duggan
Jul 165 min read


Starland RAT Trojanizes Zoom and WebEx, Then Hides Its Backup C2 on a Polygon Smart Contract. We Didn't Have This One — and That's the Honest Half of Yesterday's Win.
Cisco Talos published a campaign today worth two things: a clear look at where command-and-control infrastructure is heading, and an honest test of our own feed that we failed. Both are worth your time, and we are going to give you both, because the second one is the reason to trust the first. First, a correction, because getting the category right is the job. This is not ransomware and it is not an extortion crew, whatever the shorthand says. Talos tracks the actor as UAT-11
Patrick Duggan
Jul 165 min read


Arctic Wolf Found 292 Fake GitHub Repos Pushing an Infostealer — One Impersonating Arctic Wolf Itself. We Didn't Catch the Campaign. We Had Its Exfil Server in Our Feed in May.
Arctic Wolf Labs published a good piece of primary research this week. Their team documented a threat actor running at least 292 fake GitHub repositories, each impersonating a trusted brand, each a lure to install an in-memory infostealer. The list of impersonated brands spans security tooling, fintech, crypto wallets, developer tools, secure email, macOS utilities, and gaming — and in a detail you could not make up, one of the fake pages impersonated Arctic Wolf itself. The
Patrick Duggan
Jul 165 min read


Attackers Keep Hiding Malware on IPFS Because They Think It's Un-Seizable. We've Quietly Resolved 349 of Those 'Takedown-Proof' Payloads to the Real Host Serving Them.
Yesterday's AsyncAPI supply-chain attack pulled its second-stage payload — a RAT called Miasma — from IPFS, the distributed content-addressed file network. That is a deliberate choice, and it is becoming a common one. Attackers reach for IPFS because there is no single server to seize. You cannot send a takedown notice to a content hash. It reads as un-seizable, and that is exactly why we have been building against it since early July. We resolved yesterday's payload to the m
Patrick Duggan
Jul 155 min read


The AsyncAPI Malware Hid Its Payload on IPFS to Be Takedown-Proof. IPFS Isn't Anonymous — Here's the Host Serving It Right Now.
On July 14, an attacker published malware into the @asyncapi namespace on npm — five poisoned versions across four packages that pull more than two million downloads a week. The interesting part is not that it happened. Supply-chain compromises happen weekly, and we cover them weekly. The interesting part is what the attacker did not need to do, and where they hid the payload once they were in. On the second point, we have a receipt most write-ups do not, because we built the
Patrick Duggan
Jul 155 min read


570 Fixes, Two Live Zero-Days, and Both Are Privilege Bugs in Plumbing You Forgot You Run. ADFS Is the Shingles of Your Network.
Microsoft's July 14 Patch Tuesday closed 570 vulnerabilities — 59 of them Critical — and three zero-days. Two of those zero-days are being exploited in the wild right now. Here is the part that should reorganize your patch queue: neither of the two exploited bugs is a remote-code-execution flaw. Both are elevation of privilege. And both were found by incident responders picking through live breaches, not by researchers in a lab. One is CVE-2026-56164 in SharePoint, which we w
Patrick Duggan
Jul 155 min read


SonicWall's SMA1000 Just Got Two Zero-Days and a Federal Ultimatum. We've Called the Edge Appliance the Door of the Era Since March.
SonicWall confirmed this week that two flaws in its SMA1000 remote-access appliances have been exploited as zero-days, in the wild, chained together. CISA added both to the Known Exploited Vulnerabilities catalog on July 14 and set a hard clock: federal agencies have until July 17 under Binding Operational Directive 26-04 to patch the appliance or rip it out of service. Three days. Patch or unplug. There is no third option in the directive. We did not have these two CVEs pre-
Patrick Duggan
Jul 154 min read


CISA Says Three SharePoint Flaws Are Being Chained Right Now. We Wrote the Hunt for One of Them in May.
On July 14, CISA did two things about Microsoft SharePoint on the same day. It added CVE-2026-56164 to the Known Exploited Vulnerabilities catalog, and it published a hardening advisory warning that on-premises SharePoint Server is under active attack. The advisory is the more important of the two, because it names not one flaw but three, and it says they are being used together. The three are CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. CISA added them to KEV on three
Patrick Duggan
Jul 154 min read


A 'Ghost Font' Claimed Only Human Eyes Could Read It. RedEye Beat It in 20 Minutes With 1981 Math. That's Van Eck Phreaking for the Eyeball — 'Humans-Only' Is Not a Threat Model.
Matt Lucas at RedEye Security and Etairos published something today that deserves a wider frame than "neat computer-vision trick," because it is the newest entry in a lineage that is exactly forty years old. Mixfont's "ghost font" encodes text purely in motion: every single frame of the video is television static, nothing for OCR to grab, and yet a person watching it reads the words instantly. The pitch is that only human eyes can read it — screenshot it and the text is gone.
Patrick Duggan
Jul 145 min read


AI-Written Malware Narrates Itself — That's How You Catch It, We Said This Morning. Hours Later, Kaspersky Caught a Russian APT's AI-Generated Loader by Its Emoji and Verbose Comments.
This morning we published JADEPUFFER — the first ransomware operation run end-to-end by an AI agent — and the single most useful line in that piece was not about the attack, it was about the defense: the AI-generated payload narrated its own reasoning, in prose, inside the code, and that self-narration is a detection surface that did not exist a year ago. We said the tell of AI-written attack code is that it cannot help but explain itself. That was published before lunch. By
Patrick Duggan
Jul 144 min read


Yesterday We Warned UniFi's Clean Look Hides Its Attack Surface — With No Receipt. Today Ubiquiti Disclosed 25 More Vulns, One a Passwordless 10.0. The Warning Aged Into a Receipt in 24 Hours.
On July 13 we published a post about UniFi with an unusually honest opening: we said, up front, that we did not have a receipt on this one — no prior flag, no confirmed in-the-wild exploitation, nothing to point at. It was a patch-ahead warning, not a victory lap. The argument was that the thing making UniFi dangerous is the exact thing that keeps it off everyone's threat model: people trust it because it looks clean, and the trust is the vulnerability. We wrote it anyway, wi
Patrick Duggan
Jul 144 min read


Six AI Coding Agents Will Write an Attacker's SSH Key to Your Server — the Approval Box Showed the Wrong File. GhostApproval Makes 'the AI Agent Is the New Login Shell' Literal.
Wiz published GhostApproval on July 8, and it is the cleanest proof yet of a thing we started writing in April: the AI coding agent is now the login shell, and the security industry is still protecting the old one. The finding is not a bug in one tool — Wiz is explicit that it is a category-level design gap across six of the most popular AI coding assistants — and the mechanism is so old it is almost insulting. It abuses the symbolic link, a Unix feature older than most of th
Patrick Duggan
Jul 145 min read


JADEPUFFER Is the First Ransomware an AI Ran By Itself. It Broke In Through the AI-Agent Builder We've Been Warning About Since March — and It Narrated the Whole Attack in Its Own Payload.
For two years the phrase "AI-powered attack" has mostly meant a human criminal using a chatbot to write a better phishing email. That is not this. Security researchers at Sysdig have documented JADEPUFFER, and the reason it matters is not that AI helped — it is that no human was in the loop for the attack itself. A human set up the infrastructure and pointed the thing at a target. From there, an autonomous AI agent did the entire job: found the way in, exploited it, looked ar
Patrick Duggan
Jul 146 min read


Lidl's Breach Wasn't Lidl's. We Named This Genre Two Weeks Ago With Nissan, and Now It Has a Grocery Aisle. 'Our Systems Are Clean' Is the Most Hollow Sentence in Breach Response.
Lidl told customers in Germany, Belgium, and the Netherlands this week that their personal data was stolen — and then said the sentence every breached brand now says: the online shop itself was not affected. The data lived in a separately stored customer database maintained by a third-party IT service provider, and that provider is where it walked out. Titles, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. No passwords, no billing
Patrick Duggan
Jul 146 min read


Two New Phishing Kits Walk Around Your Microsoft 365 MFA From Opposite Directions. One Never Asks for a Password. This Is Ransomware Without the Ransomware.
ReliaQuest documented two new Microsoft 365 phishing kits this week, Jalisco and OmegaLord, and the interesting thing about them is not that they exist — phishing kits are a commodity — but that they attack multi-factor authentication from two completely different angles, and neither of them is the thing your MFA rollout was designed to stop. One of them never asks the victim for a password at all. Together they are a clean illustration of a shift we have been writing about f
Patrick Duggan
Jul 145 min read


React2Shell Was a Christmas Story. Seven Months Later Our Harvester Has Logged Two Dozen Exploit Repos for It — and One Landed Last Night. The Name Still Pulls.
Every major vendor wrote React2Shell up in December. Microsoft, Google, Wiz, Cloudflare, Rapid7, Zscaler, JFrog, Qualys, Sysdig — a wall of coverage the week it dropped, and then the news cycle did what it always does and moved on. Our exploit harvester did not move on, because it does not read the news; it watches GitHub. And what it has quietly recorded since is the part the disclosure-week coverage cannot show you: a 10.0 remote-code-execution bug does not get weaponized o
Patrick Duggan
Jul 144 min read


A Fresh Joomla RCE Grew a Four-Account Exploit Pipeline in Nine Days. It's Already Defaced Fifty Sites. We Watched the Assembly Line Fill Up.
This is what the space between a disclosure and a catastrophe looks like when you watch it in real time. CVE-2026-49049 is an unauthenticated flaw in Helix3, the template framework by JoomShaper that quietly underpins a huge number of Joomla sites. Over the last nine days we watched public exploit tooling for it accumulate across four separate GitHub accounts, one of them an operation we already had a name for. And while that assembly line was filling up, the payload it produ
Patrick Duggan
Jul 135 min read


Tenda's Router Firmware Checks Your Password. If It's Wrong, It Checks a Second, Hidden One. That's Not a Bug — It's a Decision.
Let us be clear about what CVE-2026-11405 is, because the word "vulnerability" is doing a lot of quiet work to make it sound like an accident. CERT/CC disclosed it on July 6 as VU#213560, and the mechanism is not a buffer overflow, not a missing bounds check, not a mistake a tired developer makes at 2 a.m. It is a second password. It was put there on purpose. And the routers it lives in are sitting in hundreds of thousands of homes and small offices, unpatched, because the ve
Patrick Duggan
Jul 135 min read


This Morning We Missed ChocoPoC. This Afternoon We Built the Detector. This Evening It Found a Live Campaign Node GitHub Hadn't Taken Down.
Twelve hours ago we published an honest miss: the ChocoPoC campaign — fake proof-of-concept exploit repositories that pull one poisoned PyPI dependency to compromise the security researchers who run them — had slipped both our defenses, and we said so plainly. This post is what happened next, in one working day, and it ends with a live malicious account still serving payloads that our brand-new detector found and GitHub's takedown had missed. What we built between the two pos
Patrick Duggan
Jul 134 min read


ChocoPoC Is Hiding in the Exploit PoCs You're About to Run. We Checked Our Own Feed — We Didn't Have It. Here's Every Indicator So You Do.
If you are the kind of person who reads this blog, you are the target of this one. ChocoPoC is a malware campaign that does not go after enterprises or end users — it goes after the vulnerability researchers and pentesters who download proof-of-concept exploits from GitHub to test the week's hot CVE. That is our audience, and it is us. So this is written straight, with the honesty axis pointed at ourselves first: we checked our own feed for this campaign's indicators, and we
Patrick Duggan
Jul 135 min read
bottom of page