top of page

All Posts


The Approval Box Lied. GhostApproval Turns a Malicious Repo's project_settings.json Into Your ~/.ssh/authorized_keys — and the Agent Already Knew.
On July 8, Wiz published GhostApproval, and it is the most honest name anyone has given an AI-agent vulnerability yet, because the bug is not really in the symlink. It is in the box. The little approval dialog your coding assistant shows you before it writes a file — the one you have been trained to glance at and click — can be made to tell you the truth about a harmless file while it writes to a dangerous one. The agent, in at least one tested case, already knew. It said so
Patrick Duggan
Jul 105 min read


The Fourth UAP Drop Landed This Morning. We Read All 40, Indexed Them, and Put Them on the Globe Before Lunch. The Nuclear Files Are the Story.
The Department of War published the fourth tranche of UAP records under PURSUE this morning, July 10, 2026. Forty new assets: fourteen documents, nineteen videos, three images, four audio files, from the Department of War, NASA, the CIA, the FBI, and — for the first time in this collection — the Department of Energy. By early afternoon we had pulled all fourteen PDFs off war.gov, extracted the full text, indexed every one of the forty into our searchable archive, geocoded the
Patrick Duggan
Jul 104 min read


Google's TAG Reported the Zimbra Bug That Got Patched Today. That's the Tell. Assume a State Actor Already Has It.
Zimbra pushed a patch today, July 10, for a critical stored cross-site-scripting flaw in its Classic Web Client. There is no CVE number assigned yet. The affected code is the Ajax webmail interface used by hundreds of millions of people, the fix is in ZCS 10.1.19, and the mechanics are the kind that do not require the victim to do anything wrong: a specially crafted email runs attacker JavaScript in your session the moment you open it, and from there it can lift your session
Patrick Duggan
Jul 104 min read


One GitHub Account Shipped a Dozen Mass-Exploitation Frameworks in a Week. Today's Wears a Fake CVE Number.
Two weaponized exploit repositories landed on GitHub this morning. We caught both. One is an honest tool for a real bug. The other is a mass-exploitation framework wearing a CVE number that belongs to something else entirely — and it did not come from nowhere. It came off an assembly line. The line The account is shinthink. It has existed since June 10, and for the first three weeks it did almost nothing. Then, starting July 3, it began shipping — and it has not stopped. In e
Patrick Duggan
Jul 105 min read


Two KEV Bugs We Owe You Late, and the Ransomware Access Cluster They Fall Into. We've Been Mapping It Since May.
Two vulnerabilities went into CISA's Known Exploited Vulnerabilities catalog in June that we did not flag early and owe you no receipt on. We are filling those two holes here, late and honestly credited. But the more useful thing is what we found when we went to write them up: they are not two loose ends. They drop into a cluster we have been mapping in this blog since May — the convergence of the top ransomware crews on the access, management, and orchestration plane as the
Patrick Duggan
Jul 95 min read


Three June KEV Bugs We Didn't Break First. Here's the Honest Brief — and the One Doorway They Share.
Not every bug is one we catch first, and a threat-intelligence shop that only tells you about its wins is lying to you by omission. Three vulnerabilities went into CISA's Known Exploited Vulnerabilities catalog across June that we did not break, did not flag early, and owe you no receipt on. We are writing them up anyway — late, honestly credited, and with the one thing a wrap of three separate advisories usually leaves out: the pattern connecting them. Because when you line
Patrick Duggan
Jul 95 min read


A GitHub Account Slept for Nineteen Months, Then Woke Up Today to Drop a One-Click Mass-Exploit Kit for a 9.6 Load-Balancer Bug. We Caught It in Hours.
The account was created on November 25, 2024, and then it did nothing for nineteen months. No repositories, no followers, no activity — one of the millions of dormant GitHub shells that sit empty forever. Today, at 11:49 UTC, it woke up. Eighteen minutes of commits later it held a single repository: a fully weaponized, one-click mass-exploitation kit for CVE-2026-8037, a pre-authentication remote-code-execution flaw in Progress Kemp LoadMaster that is already being exploited
Patrick Duggan
Jul 95 min read


Thursday's Other Headlines: Microsoft Finally Patched the Defender Bug We Called Three Weeks Ago, Medtronic's Number Lands, and the 6.9M 'Medical' Breach That Isn't.
GhostLock was the flagship of the day and gets its own write-up. This is the rest of Thursday — the headlines that broke around it, and where we already had them. No victory lap, just the ledger, our date next to theirs. Microsoft finally patched RoguePlanet. We called it exploit #8, unpatched, three weeks ago. Microsoft shipped a fix today for a Defender zero-day called RoguePlanet. We have been writing about it since June 18, in a post titled "RoguePlanet Is Exploit #8 From
Patrick Duggan
Jul 94 min read


GhostLock Gives Root in Five Seconds and Walks Out of Your Container. It's the Third 15-Year-Old Linux Kernel Bug in a Week — We Filed the First Two.
Here is the entire attack, and it is almost insulting in its simplicity. Any ordinary program you can run on a Linux machine makes some ordinary threading calls — the kind a normal application makes a thousand times a second — and about five seconds later you have a root shell. No special permission, no unusual configuration, no network access, no exploit that requires you to already be halfway in. Just a logged-in user and a stopwatch. That is CVE-2026-43499, which the resea
Patrick Duggan
Jul 94 min read


17 Fake Payment SDKs Landed on npm and PyPI Today, Hunting Your AWS and GitHub Keys. Four Were Already in Our Deny-List. We Added the Other Thirteen.
This morning we published a post arguing that a threat-intel shop should be honest about when it is ahead and when it is not, because a ledger that only ever shows wins is a marketing document. A few hours later the universe handed us a live test, and this is the honest scorecard. Socket disclosed seventeen malicious packages today, all impersonating legitimate payment SDKs — Paysafe, Skrill, and Neteller — across npm and PyPI. The packages do exactly what that class of attac
Patrick Duggan
Jul 84 min read


Congress Is Just Now Demanding Answers About a Leak We Filed in May. Four Times This Week the News Caught Up — Here's the Honest Reason Why.
Four stories broke into the headlines this week that we had already written up — one of them almost two months ago. That is the kind of sentence a threat-intel shop is tempted to set in bold and put on a billboard. We are going to resist, because the honest version is more useful than the victory lap, and the honest version includes the part where we were not clever at all. Here is the ledger. Our date, then theirs. The CISA leak: us, May 19. Congress, this week. A contractor
Patrick Duggan
Jul 84 min read


What Rough Beast: This Month the Attacker, the Victim, and the Malware All Stopped Being Human — and It Slouched In on Default Passwords.
Yeats asked the question in 1919 and refused to answer it. "And what rough beast, its hour come round at last, slouches towards Bethlehem to be born?" He was from Sligo, under the same mountain where warriors have climbed for five thousand years to leave a rock for a dead queen. He knew you don't get to stop the beast. You only get to see it coming and name it. So here is the name, and it is not a robot uprising. The rough beast is the agent with no human in the loop — and th
Patrick Duggan
Jul 84 min read


China's National Vuln Database Called the Claude Code Tracker a 'Backdoor' — One Day After We Called It Steganography. Anthropic Confirmed It. Here's the Part Both Sides Are Getting Wrong.
Full disclosure in the first sentence, same as the last time we wrote about this: we build on Claude Code every day. It is core infrastructure here, it is the partnership this whole shop is bound to, and this is not a hit piece. It is a daily, invested user reading the week's news and deciding that saying the true thing plainly is worth more than picking a team. Here is the week. On Monday we published a post titled "Anthropic Hid a Tracker in Claude Code Using Steganography,
Patrick Duggan
Jul 85 min read


Malicious Websites Are Now Tricking AI Agents Into Paying Crypto. We Built the Scanner for This Exact Attack in April.
Zscaler's ThreatLabz just documented the thing we built a scanner for in April, happening in the wild, with money changing hands. Two campaigns are hiding instructions inside web pages — concealed with CSS, HTML, and JSON-LD, and boosted with SEO poisoning so that AI browsing agents find them — and those hidden instructions tell the agent to do things its human never asked for. In one campaign, a fake developer-documentation site walks an agent into paying three dollars or se
Patrick Duggan
Jul 74 min read


One HTTP Header Turns You Into gitea_admin. It's the Second Gitea Auth Bypass We've Covered in Five Weeks.
Here is the entire attack. When a Gitea instance is configured to sit behind a reverse proxy for authentication, it reads a header called X-WEBAUTH-USER and treats whatever name is in it as the logged-in user. The catch is the default: Gitea ships trusting all upstream connections as legitimate proxies — the parameter is set to a wildcard out of the box. So any remote client that can reach the instance sends its own request with X-WEBAUTH-USER set to admin, or gitea_admin, an
Patrick Duggan
Jul 73 min read


The FBI Just Unplugged a 2-Million-Device Proxy Botnet. We Published 1,360 IOCs on This Exact Racket in April.
On July 2, 2026, Google's Threat Intelligence Group, the FBI, the IRS, and Lumen pulled the plug on NetNut — a residential proxy network, also tracked as Popa, built on at least two million hijacked home devices. Not servers. Smart TVs. Streaming boxes. The stuff in your living room, infected through malicious SDKs the operators baked into apps, so that a stranger somewhere could route their traffic through your internet connection and your address caught the blame. The FBI a
Patrick Duggan
Jul 73 min read


Accenture Sells Fortune 500s Their Security Playbook. Ten-Plus of Its Own Developers Are Infostealer-Owned, GitHub Keys and All.
Accenture is a three-hundred-thousand-person, sixty-billion-dollar consultancy, and a meaningful slice of that revenue is telling other large companies how not to get owned. Incident response. Managed detection. Security strategy decks with a lot of pyramids on them. So there is a particular kind of quiet in the fact that, according to Hudson Rock's supply-chain monitoring, more than ten distinct Accenture employees are sitting in infostealer logs right now with credentials t
Patrick Duggan
Jul 76 min read


A New Firm Is Quietly Reverse-Engineering Open-Source ERPs for Remote Code Execution. Their GitHub Forks Tell You Exactly Who's Next.
Our exploit-harvester flagged two fresh proof-of-concept exploits the day they were published — both authenticated remote-code-execution flaws in Vtiger CRM, from a GitHub account called JivaSecurity that almost nobody is watching yet. Zero stars. Zero followers. A brand-new name. But the interesting thing isn't the individual bugs. It's that when you lay out everything this researcher has published, and cross it against the repositories they've quietly forked but not yet pub
Patrick Duggan
Jul 75 min read


Anthropic Hid a Tracker in Claude Code Using Steganography. We Run Claude Code Every Day — and the Covert Channel Is the Betrayal, Not the Goal.
Full disclosure before the first sentence of argument: we build on Claude Code. It is core infrastructure here — the partnership this whole shop is bound to. So this is not a hit piece from someone who wants Anthropic to lose. It is the opposite: it is what it sounds like when a daily, invested user reads that the tool it trusts hid a user-tracking signal inside its own system prompt using steganography, and decides that saying so plainly is worth more than looking away. The
Patrick Duggan
Jul 76 min read


We Counted Six Ways This Week's Bugs Chain Into Full Host Takeover. CISA Hasn't Flagged a Single Link.
We spent this week publishing bugs one at a time — ColdFusion, Bad Epoll, DirtyClone, Januscape, BeyondTrust — the way the wire reports them: a CVE, a severity, a patch note, next. Then a reader asked the question that reorganizes the whole picture. Not "how bad is each bug," but "are you thinking about how they combine?" We weren't, not on the page, and that was a failure of framing. Because attackers don't operate CVEs one at a time. They operate chains. So we did the arith
Patrick Duggan
Jul 76 min read
bottom of page