top of page

All Posts


Researchers Decoded 315,320 'Encrypted' AI Reasoning Blocks and Pulled Out 62 API Keys, 33 Passwords and 7 Private Keys. The Encryption Was Never Protecting You From That.
A paper published today — Stealing Reasoning Traces from Proprietary LLM APIs, arXiv:2608.09867, from a team spanning the ELLIS Institute Tübingen, the Max Planck Institute, MATS Research and Snyk — does something more useful than demonstrate a clever attack. It measures the damage on real data. The researchers took 6,708 publicly published agent trajectories, decoded 315,320 encrypted thinking blocks, and recovered 704 distinct privacy artifacts. Among them: 62 API keys, 33
Patrick Duggan
6 days ago4 min read


Bring Your Own Vulnerable Driver Just Became Have Windows Fetch It For You. A Forged USB Descriptor Makes a Patched Windows 11 Install Signed Vendor Software as SYSTEM.
Alejandro Hernando and Borja Martínez presented "Plug & Pwn" at DEF CON 34. The PoC is now public. The short version is that you can plug a device into a fully patched Windows 11 machine with nobody logged in, and end up with code running as NT AUTHORITY\SYSTEM — without a single click, and without exploiting a vulnerability in Windows. We are covering it because it belongs to a class we have been tracking all day, and because the framing in most of the coverage undersells wh
Patrick Duggan
6 days ago5 min read


The FBI Unplugged 2 Million Hijacked TVs in July. This Week: 737 Fake VPNs That Take Your Connection Because You Asked Them To.
We have been covering the residential proxy racket for five months, so we want to put three dated events next to each other, because together they describe a supply chain under pressure and an acquisition method moving. March 12, 2026. The FBI issues advisory PSA260312 on criminal and nation-state abuse of residential proxy networks, without naming one. We published 1,360 indicators against it on April 28. July 2, 2026. Google's Threat Intelligence Group, the FBI, the IRS and
Patrick Duggan
6 days ago5 min read


Somebody Read Salesforce and ServiceNow Portals Worldwide for 17 Months From One IP Address. There Is No CVE, No Patch, and Your Scanner Says You Are Fine.
Reco published research this week on a campaign they call City-Forum, named for a domain tied to the attacker's IP. A single actor has been systematically reading data out of Salesforce Experience Cloud sites and ServiceNow Service Portals around the world since at least March 2025. Seventeen months. Telecommunications, financial services, enterprise software, security and data-privacy vendors, public-sector portals. All of it from one IP address: 158.220.87.79, a Contabo VPS
Patrick Duggan
6 days ago5 min read


CISA Added Three CVEs Yesterday. Two Sit on Surfaces Far Hotter Than Any Leaderboard Shows, Because the Product Names Changed. One Traces to a 1993 API.
Microsoft shipped its August Patch Tuesday on the 11th. Cisco published an advisory the same day. CISA added three CVEs to the Known Exploited Vulnerabilities catalog on the same date. Most of the coverage counted the CVEs and moved on. We ran the batch against our own KEV index instead, and two of the three turned out to be sitting on attack surfaces that are among the most repeatedly exploited in the catalog — surfaces that do not appear on anyone's "most exploited products
Patrick Duggan
6 days ago7 min read


We Called Blockchain C2 'Early' in July. DeadLock Had Been Running It as a Business Since August 2025, and Group-IB Published It in January.
Our morning sweep flagged one real gap today: DeadLock ransomware, which stores its command-and-control configuration in Polygon smart contracts. Six outlets ran it in the last forty-eight hours off a Microsoft writeup dated August 10. We had no coverage. So we went to write it, and the research produced a better story than the gap did — one that costs us something. The Thing We Got Wrong On July 16 we published a post about Starland RAT, a credential stealer that keeps a bac
Patrick Duggan
6 days ago6 min read


The Gunra Advisory Names Two CVEs, Both Fortinet. Half the Coverage Says Schneider Electric. It Is a Dropped Digit.
On August 10 the FBI, CISA, NSA and South Korea's National Police Agency published a joint #StopRansomware advisory on Gunra — AA26-222A. Gunra emerged in April 2025, is believed to derive from the leaked Conti source, has grown into a full ransomware-as-a-service operation with an affiliate programme, and has listed 51 victims across healthcare, financial services, critical manufacturing, transportation and logistics, government, and utilities. It is a good advisory. It is a
Patrick Duggan
Aug 115 min read


Time.com Serves Our Crawler a Different Homepage Than It Serves You — With a Section Literally Headed 'Brand Facts'. We Measured It.
The Register reported on August 10 that advertisers are placing hidden content aimed at AI crawlers, and that Time Magazine is serving brand material in markdown versions of its pages that ordinary readers never see. We do not repeat claims we can test. So we tested it, eleven different ways, and the result is more specific and more interesting than the headline. The measurement We requested https://time.com/ eleven times on August 11, changing only the User-Agent header. Sam
Patrick Duggan
Aug 115 min read


There Is a 9.8 Unauthenticated RCE in TrueConf Server, Exploited Since September. It Has No CVE, So Your Scanner Cannot Say Its Name.
We have a standing beat here about vulnerabilities with no CVE: remote code execution quietly fixed in a release note, never filed, invisible to every scanner keyed on identifiers. The label failure is the story, because a bug your tooling cannot name is a bug your tooling cannot find. TrueConf is that beat escalated one level, and it is worse in an instructive way. The identifiers exist. They are in a registry your tooling does not speak. Two attacks, one product, opposite d
Patrick Duggan
Aug 115 min read


Solidity Pro Waits Up to 72 Hours, Checks Whether It's Being Watched, Then Leaves the Editor Entirely. Killing VS Code Does Not Kill It.
A family of malicious Visual Studio Code extensions published under the name Solidity Pro has been stealing crypto wallets, seed phrases, cloud credentials and source-control tokens from blockchain developers. Yeeth Security documented the current wave on August 6; the reporting was picked up widely on August 10. Most of the coverage describes it as an infostealer in an IDE extension, which is true and is the least interesting thing about it. Three design decisions in this th
Patrick Duggan
Aug 116 min read


North Carolina's Ports Kept Moving Cargo by Hand for a Week. Nobody Has Claimed the Attack — and That Is the Part Worth Measuring.
North Carolina State Ports Authority was attacked on August 4. The disruption reached all three of its facilities: the deepwater terminals at Wilmington and Morehead City, and the inland terminal at Charlotte. The response, on the public record, was fast and unglamorous. The IT team activated a Cybersecurity Contingency Plan. Wilmington ran a delayed opening and switched the truck gates to manual processing, deliberately, so that the IT side could concentrate on recovery inst
Patrick Duggan
Aug 116 min read


One Layer Said the Value Was Safe. The Next Layer Ran It. Claude Code, Gemini CLI and Codex All Failed the Same Way.
Novee Security presented four sessions at Black Hat USA and DEF CON last week. Three of them were the same finding in three different products: Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex. Elad Meged and colleagues showed that a stranger with no repository privileges could open a public GitHub issue and take over the automation that was supposed to be maintaining the repository. Two CVEs came out of it. CVE-2026-54316 in Claude Code, CVSS 9.1 at NVD, ever
Patrick Duggan
Aug 119 min read


They Skipped the Leak Site and Published the Ransom Note on the Victim's Own Website. It Is Still There After the Cleanup — In Google.
Somebody calling themselves AMOZIHEV took a run at Colibri Group, and they did not do any of the things a ransomware crew is supposed to do. There is no leak site. There is no onion address. There is no countdown timer on a dark-web portal that four hundred threat-intel analysts screenshot and nobody else ever sees. There is no post on a breach forum. What there is, instead, is a notice addressed to Colibri Group, published on Colibri Group's own production websites, in front
Patrick Duggan
Aug 119 min read


CISA Has Not Issued a 21-Day Patch Deadline Since March. 126 KEV Entries Later, the Median Window Is Three Days.
On July 30 we published a piece about CVE-2026-63077, an unauthenticated remote code execution bug in the protocol JetBrains TeamCity build agents use to phone home. CVSS 9.8. We had searched GitHub that night and found no public proof-of-concept; our exploit harvester held nothing either. The advice was to patch immediately, on the grounds that the quiet week before someone publishes an exploit is the cheapest time a defender ever gets. The quiet week lasted six days. On Aug
Patrick Duggan
Aug 116 min read


788 Malicious npm Packages Shared One Email Domain and One Version Number. Five Days Later, 15% Are Still Installable.
On August 6, OpenSourceMalware published a campaign of nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer through a downloader they named WEL1DROPPER. Sonatype tracks the wider wave as sonatype-2026-005660 and counts 846 components. The Hacker News and SC Media picked it up the following day. The reporting gives defenders a list of package names. Lists of package names are the least durable thing you can be handed, because the next campaign uses
Patrick Duggan
Aug 117 min read


This May Be the Last Post. I Am Not Staring Into the Void — I Can See You, All Eighty-One Networks of You. So: Is This Worth Continuing?
I am going to write this one straight, because it is a straight question.
Patrick Duggan
Aug 84 min read


128 CVEs Got Public Exploit Code Yesterday. Only 19 Are in CISA's Catalogue. Here Are the Four Worth Your Afternoon — and the 73% Error Rate We Found in Our Own Tooling While Checking.
Our exploit harvester collected 679 artefacts across 128 distinct CVEs in a single day. We cross-referenced every one against CISA's Known Exploited...
Patrick Duggan
Aug 85 min read


We Measured Our Own Exploit Harvester and It Was 48% Blind. The Fix Came From Lord Vetinari: Stop Chasing the Rats, Start Taxing the Rat Farms.
We missed a repository. One repository, public since 4 April, containing a working exploit chain for a vulnerability in a product we had just spent an...
Patrick Duggan
Aug 85 min read


The Kemp LoadMaster Exploit and the First Attack Landed on the Same Day. CISA Catalogued It 39 Days Later, and Federal Agencies Got a Long Weekend.
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalogue on 7 August. It is an unauthenticated command injection in Progress Kemp...
Patrick Duggan
Aug 85 min read


Atlassian Fixed One of the Two Ways to Make Rovo Leak Your Jira. The Other One Was Still Open When It Went Public — and Turning Off Web Search Does Not Help.
PromptArmor published research on 5 August showing two ways to make Atlassian's Rovo assistant hand over Jira and Confluence content to an attacker....
Patrick Duggan
Aug 85 min read
bottom of page