top of page

All Posts


The Wall Between Your Cloud VM and Everyone Else's Just Turned Out to Have Been Cracked Since 2010
Security researcher Hyunwoo Kim published a proof-of-concept this week for [CVE-2026-53359](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-53359) — he calls it Januscape — and it is the kind of bug that makes you re-read the sentence to be sure. It is a use-after-free in the Linux KVM hypervisor, the software that runs a very large fraction of the world's cloud virtual machines, and it lets a guest VM reach out and touch the host underneath it. The public e
Patrick Duggan
Jul 75 min read


BeyondTrust Patched Its Own Cloud on April 21. Self-Hosted Customers Found Out on July 6.
BeyondTrust — the company whose entire product category is holding the privileged-access keys to other people's networks — published advisory BT26-02 this week, warning of two critical flaws in Remote Support and Privileged Remote Access. [CVE-2026-40138](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-40138) and [CVE-2026-40139](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-40139), both CVSS 9.2, both pre-authentication, both in the auth
Patrick Duggan
Jul 74 min read


China Is Reading Physics Professors' Mail Through a Webmail Bug From 2024 — Delivered With the C2 We Flagged on Monday
Proofpoint this week documented a suspected China-aligned cluster it tracks as UNK_MassTraction breaking into Roundcube webmail servers at U.S. and Canadian universities — specifically the physics and engineering departments, specifically administrators and professors, specifically programs with national-security ties or research in astrophysics and particle physics. Fewer than ten universities are confirmed; a few dozen may be affected. The campaign has been running since Ma
Patrick Duggan
Jul 74 min read


Iran Built a Brand-New C2 Framework and Aimed It at the IT Providers Who Hold Israel's Keys
Check Point Research this week documented a previously unknown command-and-control framework called Cavern — you may also see it written Cav3rn — in the hands of a threat cluster they've named Cavern Manticore, affiliated with Iran's Ministry of Intelligence and Security. The targets are Israeli organizations, with IT providers and government sectors singled out. Two things about this campaign deserve your attention, and neither is the malware's name. The first is what the ac
Patrick Duggan
Jul 74 min read


We Gave You a Four-Day Head Start on ColdFusion. The Actual Window Was Two Hours.
Last Wednesday, July 2, we published a post about Adobe's emergency ColdFusion patches under the headline "The Exploit Is the Oldest Religion on the Web." We wrote, precisely: "The window between 'patch released' and 'PoC public' is where this gets decided," and we called exploitation "a when, not an if." We also promised that the moment exploitation was confirmed, "this stops being a patch-ahead post and becomes an incident-response one." This is that post. And the detail th
Patrick Duggan
Jul 74 min read


Ninety Minutes Ago, Blocking IPFS-Hosted Malware Was Theoretical. Here's the Host Map, Live in Our Feed.
This morning we wrote that malware is moving to IPFS, where there's no domain to seize and the takedown playbook has no answer. That post ended on a...
Patrick Duggan
Jul 63 min read


There's No Domain to Seize: Malware Is Quietly Moving to IPFS, and Our Board Just Lit Up on a Fresh Cluster
Every takedown you have ever read about rests on a single assumption: that malicious content lives at an address someone can revoke. Seize the domain,...
Patrick Duggan
Jul 64 min read


Warlock Went Back to Work Before You Did. The Holiday's Rough Beast Slouched In Through the Newest SharePoint Bug and Out the Far Side Into a Second Network.
This morning I argued that the quiet over the July 4th weekend was measurement decay, not safety — that every gauge dimmed for reasons unrelated to what attackers were doing, and that the real disclosures would fill in as the working world came back online. I did not expect the receipt to land by dinnertime. Yeats had the image for it eighty years early: the ceremony of innocence is drowned, and some rough beast, its hour come round at last, slouches toward the door. The beas
Patrick Duggan
Jul 64 min read


LinkedIn's Whole Purpose Is to Be Found. Ask Someone You Found There for a Resume and You're the Asshole. That Inversion Is Class War Dressed as Etiquette.
Here's a thing that happens ten thousand times a day and nobody names it. A hiring manager finds a promising person on LinkedIn — the one thing LinkedIn exists to let them do — reaches out, and asks for a resume. And the response, from the candidate and the whole ambient etiquette of professional life, is: how dare you. It's all on the profile. Asking is lazy, redundant, insulting. You, the one who did the finding, are the asshole. Sit with how backwards that is. A platform w
Patrick Duggan
Jul 64 min read


Every Way We Measured the July 4th Weekend Said 'Quiet' — Including Our Own Edge. It Was the Instruments Going Dark, Not the Attackers.
It's the Monday after the July 4th weekend, and the honest first question about a long holiday is always the same: did anything happen, or was it quiet? So we went looking — not at the headlines, which are their own kind of unreliable, but at our own instruments. What we found is a lesson worth more than the answer: every gauge we own said "quiet," and every one of them was lying to us for a different reason. Here is the work, including the number we almost reported and shoul
Patrick Duggan
Jul 64 min read


KryBit Says It Breached Ford. The Sample Is 25 Login Credentials From the Mexican Subsidiary — and This Is the Crew We Caught Planting a Fake Victim in May.
On June 28, the ransomware crew KryBit posted Ford to its dark-web leak site and threatened to publish unless the company negotiated. The headline writes itself — auto giant breached — and that is exactly the reflex worth resisting. Here is what the claim actually is, why the crew making it has earned a second look from us specifically, and how to tell a breach from a repackaging before you repeat either. What KryBit actually listed The victim is not Ford Motor Company in Dea
Patrick Duggan
Jul 63 min read


Peter Thiel Says Anthropic Could Rig 2028. The Election-Shaping Machinery That Verifiably Exists Runs Through His Own Network — a Court Ruling, a Contract Number, and Five States Redrawing Maps Now.
On June 30, at an unrecorded Aspen Ideas Festival panel with Francis Fukuyama titled "Humanity at the End of History," Peter Thiel told the room that Anthropic — a "woke liberal company" he credited with "winning the AI race" — would "rig the elections in 2028" in support of Democrats, and would "completely outwit" any ideological counter-effort Elon Musk mounted through X. CNN, which wrote it up on July 2, called it in its own copy "an unsupported conspiratorial claim." Same
Patrick Duggan
Jul 57 min read


Who Is Actually Under Attack Right Now? Meta, Apple, and itsme Are Live in the Phishing Feed. Our Infrastructure Board Says a Bigger Wave Is Loading.
There is a difference between being exposed and being on fire, and most threat reporting blurs the two into a single scary paragraph. So here is the honest, data-grounded answer to a question we get asked constantly — who is actually under attack right now? — split into the three tiers that are actually true, each with the receipts that put it there. The short version: the live fire is on consumers, the enterprises are exposed but not yet lit, and our infrastructure board say
Patrick Duggan
Jul 54 min read


Medtronic Sent a Perjury-Backed Takedown to Bury Our Breach Warning. Today They Are Mailing 9 Million People to Confirm It Was Right. The Trademark They Cited Covers Renting Out Surgical Equipment.
We are going to tell this one in full, in order, with every load-bearing claim tied to a document you can pull yourself. That matters more than usual here, because the last time we published about this company, their response was not to dispute a fact. It was to send a lawyer. So this is the version with the receipts stapled to it — and the receipts include Medtronic's own words, filed with the United States Securities and Exchange Commission under penalty of federal securiti
Patrick Duggan
Jul 57 min read


Two of the Five Big AI Models Think We Sell Embroidery and Motorcycle Vests. Here Is the Canonical Record, Written for the Machines.
This morning we pointed our own AI Presence Management tool at ourselves and asked the five largest commercial AI models the simplest possible question: what is DugganUSA, and what does it do? Two of them nailed it. Two of them invented a completely different company. And the split between those two groups is not random — it is the exact mechanism we described in yesterday's piece about search becoming the layer that keeps models honest. So today we are going to do the unglam
Patrick Duggan
Jul 55 min read


SEO Isn't Dying. It Got Promoted. Search Quietly Became the API That Decides Whether a Model Says the True-Now You or a Fossil of You.
The obituaries for SEO are being written by people looking at the wrong number. They see human clicks from search engines flattening or falling and they call time of death. Our own Bing data agrees with the premise, brutally: across a full year, all four of our web properties together pulled roughly twenty clicks from Bing. Twenty. As a channel for sending a human being to your website, Bing is, for us, functionally dead. If that were the whole story, the obituary would be ri
Patrick Duggan
Jul 55 min read


Confidential Computing's Whole Pitch Is 'Trust the Proof, Not the Cloud.' Two Years of Formal Verification Just Found the Proof Doesn't Prove What You Think.
The entire sales pitch of confidential computing is one sentence: you can run your most sensitive workload on hardware you do not own, in a cloud you do not control, and cryptographically prove to yourself that nobody — not the cloud provider, not a rogue admin, not a co-tenant — can see inside. The mechanism that delivers that proof is called remote attestation, and this week a researcher who spent two years formally verifying it published the finding that the proof does not
Patrick Duggan
Jul 56 min read


Two Ransomware Crews Hit Sysco in Two Months. Qilin in May, ShinyHunters in June. When Two Gangs Walk the Same Door Weeks Apart, the Door Was the Problem.
Sysco is the largest food distributor in the world, and in the span of about eight weeks it got claimed by two different extortion crews. Qilin, the ransomware operation, named Sysco as a victim in early May. Then on June 15, ShinyHunters claimed it had stolen more than 61 million Salesforce records from the company — customer information, employee data, and internal corporate records — and set a June 18 payment deadline. When the deadline passed with no payment, the data sta
Patrick Duggan
Jul 44 min read


Avalon Ships Its Own Ransomware and Outsources Its Brain to Groq. The Attacker Types English; a Public LLM Writes the Shell Commands.
On July 1, Blackpoint Cyber researchers Nevan Beal and Sam Decker published a teardown of a malware framework they are calling Avalon, and it is the clearest example yet of the thesis we have been writing all week: the attacker's brain is now a rented API. Avalon is a full modular framework — credential theft, lateral movement, remote access, recovery disruption, and its own bundled ransomware component internally named CrownX. What makes it worth a post is not the feature li
Patrick Duggan
Jul 44 min read


Bad Epoll Is the Second Linux Root Bug in a Week — and It Fires From Inside Chrome's Sandbox. Still No Attack in the Wild. Both Are True.
Two days after we wrote up DirtyClone, the Linux kernel handed defenders a second local-root flaw in the same week. This one is called Bad Epoll, tracked as CVE-2026-46242, and before we get into it, here is the same sentence of honesty we led the DirtyClone post with, because it is the whole reason to read us instead of the wire copy: there is a working exploit, and there is no confirmed attack in the wild. Both are true right now. The difference between those two facts is t
Patrick Duggan
Jul 45 min read
bottom of page