top of page

All Posts


The Alibaba Thread: Five Chinese APT Operations, One Cloud Provider
Over the past 72 hours we published a spy trilogy, a PlugX investigation, and indexed 40 IOCs from weekend breaches. When we cross-referenced the new...
Patrick Duggan
Apr 134 min read


Someone Is Impersonating Claude to Install Chinese Malware. We Found the C2 Cluster.
A fake website offering a "Pro" version of Claude — the AI assistant built by Anthropic, the same AI that powers our threat intelligence platform — is...
Patrick Duggan
Apr 134 min read


Trust Is the Vector. Every Major Attack This Week Exploited Something You Trusted.
This week, nine major cyber incidents made headlines. A Windows zero-day. A PDF zero-day. An npm supply chain compromise. A CPU utility hijack. A WordPress...
Patrick Duggan
Apr 126 min read


4,000 US Industrial Devices Exposed to Iran. They're Not Using Zero-Days. They're Reading the Manual.
On April 7, the FBI, CISA, NSA, EPA, DOE, and US Cyber Command published a joint advisory: IRGC-affiliated actors are connecting to internet-exposed...
Patrick Duggan
Apr 124 min read


Hims Got Hacked. Your Boner Pills Are in the Wild.
ShinyHunters — the same group that hit Ticketmaster, AT&T, Snowflake, and 165 other organizations — compromised two Hims employees' Okta SSO credentials via...
Patrick Duggan
Apr 124 min read


Your 403 Logs Are a Customer List and a Threat Roster. Here's How to Read Them.
Every API endpoint with authentication has a reject pile. Requests that came in without a key, with a bad key, or with a key that does not have the right...
Patrick Duggan
Apr 125 min read


250 Domains Audited. Intelligence Agencies, Defense Contractors, and Fortune 500s Are Checking Their AI Presence.
We launched AIPM — AI Presence Management — as a free tool at aipmsec.com. Five AI models. Seven technical signals. Contamination detection. No login...
Patrick Duggan
Apr 124 min read


Big Trouble in Big China
Just remember what ol' Jack Burton always says at a time like that: "Have ya paid your dues, Jack?" "Yessir, the check is in the mail."
Patrick Duggan
Apr 124 min read


They Stopped the Moment We Said Their Name
Earlier today we published our investigation into a persistent probe of our STIX/TAXII threat intelligence feed. One IP address. One script. 100,000...
Patrick Duggan
Apr 123 min read


One IP. One Script. 100,000 Requests. Who Is Polling Our STIX Feed From the Space Coast?
On February 7, 2026, someone started polling our STIX/TAXII threat intelligence endpoint. Every 30 seconds. From an AT&T Wireless mobile device. Geolocated...
Patrick Duggan
Apr 125 min read


9 Breaches, One Weekend. We Had the IOCs for All of Them.
Between Friday April 11 and Saturday April 12, nine organizations got hit. Ransomware. Supply chain compromises. Zero-days. Nation-state operations. A P2P...
Patrick Duggan
Apr 125 min read


How We Built a Threat Feed That's Faster and More Accurate Than the Billion-Dollar Vendors. The Short Version.
Download the PDF: How We Built a Threat Feed That's Faster and More Accurate Than the Billion-Dollar Vendors — The Short Version (4 pages, bone cardstock) Today we ship threat intelligence to 275+ organizations in 46 countries, running on about $500 a month of Azure compute, with an internal site-level false-positive rate under 0.004%. CrowdStrike's cheapest Falcon Intelligence tier is around $100,000 per year. Recorded Future's enterprise plan is $50,000+ per seat. Mandiant
Patrick Duggan
Apr 115 min read


Q2 2026 State of AI Brand Perception in Cybersecurity: The Report Is Out. We Named Names.
Download the full PDF: Q2 2026 State of AI Brand Perception in Cybersecurity (14 pages) Fifteen vendors. Five AI models. Seventy-five audits. One afternoon. That is the corpus behind our first quarterly report on AI Brand Perception in Cybersecurity, published today. We built a product called AIPM — AI Presence Management — that queries the five largest commercial AI models in parallel about a given brand and grades the answers. It lives at aipmsec.com. We have been running i
Patrick Duggan
Apr 118 min read


OpenAI Still Thinks CrowdStrike Is In Sunnyvale. Six Things Your AI Chatbot Is Telling Buyers That Aren't True.
I asked OpenAI GPT-4o where CrowdStrike is headquartered this afternoon. It told me, with complete confidence and no hedging: "CrowdStrike was founded by George Kurtz, Dmitri Alperovitch, and Gregg Marston in 2011. The company is based in Sunnyvale, California." CrowdStrike officially designated Austin, Texas as its principal executive office in 2022. That is public information. It is in their annual report. It is on their own investor relations page. A Google search for "cro
Patrick Duggan
Apr 118 min read


We Audited Our Own AI Presence. Gemini Said We're Three Different Companies.
We build a product called AIPM — AI Presence Management. It audits how the five major AI models perceive a given brand, and scores the results. 776 domains have been through it as of this morning. Today, for the first time, we pointed it at ourselves — all three of our properties — and the result was, as my father would say, instructive. Here's what Google's Gemini 2.5 Flash knows about DugganUSA LLC and its subdomains. All three queries on the same afternoon. All three answe
Patrick Duggan
Apr 117 min read


The $75 HAT That Outruns a $500 Jetson
DugganUSA lab notebook — April 10, 2026 Here's the number that made me open a text editor at 1 AM: 309 frames per second of YOLOv8s object detection at 640×640, running on a Raspberry Pi 5 with a Hailo-8 AI HAT+. For context: NVIDIA's reference benchmark for YOLOv8s at the same resolution on a Jetson Orin Nano 8GB is around 60 FPS in FP16. The Hailo-8, at INT8, on a HAT that costs one-seventh of that Jetson, delivered five times the throughput tonight. End to end — including
Patrick Duggan
Apr 1011 min read


Friday Threat Brief: WordPress Plugin Ships a RAT, Storm-2755 Redirects Your Paycheck, Iran Targets American PLCs
Six things you need to know before the weekend.
Patrick Duggan
Apr 103 min read


Two Guys, One LLC, 46 Countries. How We Built a Global Security Operation on $75 a Month.
DugganUSA LLC was filed in Minnesota on December 1, 2025. We have two people. Our Azure bill is about $75 a month. We have no office, no investors, no...
Patrick Duggan
Apr 104 min read


Same Threat Intel. Fair Price. We Just Launched Regional Pricing for 80+ Countries.
A security analyst in Lagos should not pay the same price as a security analyst in New York.
Patrick Duggan
Apr 103 min read


Your Website Is Talking to AI Models Behind Your Back. We Built the Scanner That Catches It.
There's a new class of attack that no one is scanning for. It doesn't target your servers. It doesn't target your users. It targets the AI models that read...
Patrick Duggan
Apr 105 min read
bottom of page