top of page

All Posts


Atlassian Fixed One of the Two Ways to Make Rovo Leak Your Jira. The Other One Was Still Open When It Went Public — and Turning Off Web Search Does Not Help.
PromptArmor published research on 5 August showing two ways to make Atlassian's Rovo assistant hand over Jira and Confluence content to an attacker....
Patrick Duggan
Aug 85 min read


Metabase Shipped a CVSS 10.0 With No CVE. Your Scanner Cannot See It, KEV Cannot List It, and 19,810 Instances Are Waiting on a Human to Notice.
Metabase disclosed on 7 August that a maximum-severity flaw in its business intelligence platform had already been exploited as a zero-day. An...
Patrick Duggan
Aug 86 min read


We Had UNC6671's Phishing Infrastructure Within Hours at Confidence 70. Our Auto-Block Path Ignored It. The Feed Did Not — and We Got That Wrong the First Time We Published This.
Google's threat intelligence team published research this week on UNC6671, the extortion crew formerly branded BlackFile and now operating simultaneously as...
Patrick Duggan
Aug 76 min read


A Root Shell Shipped From the Factory in 21 Firmware Images Across Two Years. ENDLESSDOORS Was Never Broken Into — It Was Built In. Six IOCs Are In Our Feed Now.
VulnCheck disclosed on 5 August that at least twenty-one router models from the Chinese vendor Zbtlink ship with a persistent remote access implant...
Patrick Duggan
Aug 75 min read


We Tried to Measure Whether AI Is Accelerating Threats. Our Own Data Says We Cannot Answer That Yet — and Here Is the Chart That Would Have Fooled Us.
Everybody in this industry is currently saying that AI is accelerating the threat landscape. We have a corpus, a CVE catalogue synced daily since 2021, our...
Patrick Duggan
Aug 65 min read


OWAReaper Survives a Full Reimage. Our Own PoC Watch Never Saw It — Because a Zero-Day Nobody Publishes Leaves No Trace to Watch For.
Proofpoint published analysis of a campaign in which TA488 — the Russian cluster also tracked as Void Blizzard and Laundry Bear — exploited CVE-2026-42897...
Patrick Duggan
Aug 64 min read


17 of the 90 KEV Entries We Can Actually Measure Were Already Weaponized Before CISA Listed Them. One by 85 Days.
We re-ran our weaponization-latency measurement this morning. It correlates three dates for every CVE in CISA's Known Exploited Vulnerabilities catalogue:...
Patrick Duggan
Aug 64 min read


ExfilSquad Quietly Delisted Analog Devices. For a Crew With No Malware and No Exploit, the Leak Site Is the Only Telemetry You Get.
Three days ago we published an adversary profile for ExfilSquad, a crew whose defining characteristic is what it does not have: no malware, no exploit, no...
Patrick Duggan
Aug 64 min read


Everest Claims 682,887 Files From a Hospital Medication Vendor — Including Firmware, Certificates and Deployment Packages. The Patient Data Is the Least of It.
On 22 July the Everest extortion group listed Omnicell on its leak site and claimed roughly 1 TB of stolen data across 682,887 files. Omnicell has not...
Patrick Duggan
Aug 65 min read


A Worm Poisoned 2,236 npm Package Versions on Tuesday. The Part That Survives Your Cleanup Lives in .claude/ and .vscode/.
On Tuesday 4 August a self-propagating worm began publishing malicious versions of the npm packages keyv and cacheable and their common dependencies. By the...
Patrick Duggan
Aug 65 min read


We Named the Wrong Russians. Six Days Later Microsoft Named the Right Ones. Here Is Why We Do Not Have to Retract It.
On 25 July we published a post about attackers compromising the captive-portal appliances that run guest Wi-Fi at hotels, poisoning DNS at the gateway, and taking Microsoft 365 accounts from travellers who never received a phishing email. The technique description was right. The indicators were right. We named APT28 — Russian military intelligence, the GRU. On 31 July, Microsoft published its own analysis of the same campaign and attributed it to Midnight Blizzard, specifical
Patrick Duggan
Aug 45 min read


135,000 Police Records Left Through a Config Setting. AppOmni Published the Fix in November 2024.
The Police National Legal Database confirmed today that names, organisations and work email addresses belonging to UK police officers, police staff, criminal justice professionals and government partners are on a dark web leak site. A crew calling itself ExfilSquad posted samples on 26 July, claiming 135,000 PNLD records alongside roughly 607,000 from the Department for Education. If you read that as a UK policing story you will take the wrong lesson from it. PNLD is one name
Patrick Duggan
Aug 35 min read


Three Fixes Shipped in Six Days. None of Them Made the Thing Safe.
If you run N-able N-central, stop reading and go patch to build 2026.3.1.7. It is being exploited right now, Huntress has confirmed it in a customer environment, and the version you are probably on was itself the fix for the last one. That is the useful sentence. The rest of this is about why three different vendors shipped three fixes in six days and not one of them means what the word "fixed" is supposed to mean. The patch that patched the patch N-able disclosed CVE-2026-18
Patrick Duggan
Aug 35 min read


We Argued This Morning That Guardrail Prompts Cannot Stop Prompt Injection. Somebody Already Measured It: The Agents Obeyed the Attacker 85% of the Time While Explicitly Told Not To.
Earlier today we published a post about three coding agents leaking their own credentials to a single prompt injection. In it we said Google's mitigation — adding guardrail prompts to the system prompt — was "asking the vulnerable component to defend itself using the exact channel that was compromised." That was an argument. We should have checked whether anyone had turned it into a number. Somebody had. Tenet Security — Ron Bobrov, Barak Sternberg and Nevo Poran — published
Patrick Duggan
Aug 25 min read


Two Actors Changed Method This Year and Both Invalidated the Lesson Their Last Attack Taught. Demonstrated Evolution Is the Only Actor Claim You Can Actually Check.
Almost everything written about threat actors is adjectives. Sophisticated. Advanced. Highly capable. None of it is checkable. You cannot falsify "sophisticated," which means you cannot be wrong about it, which means it carries no information. There is one actor claim that is checkable: demonstrated evolution. Two dated observations of the same named actor operating at measurably different tiers. Nobody has to take your word for it, because both endpoints are public and both
Patrick Duggan
Aug 25 min read


A CVSS 10.0 From 2021 Just Became Iranian Tradecraft. It Was Never Really Patchable — the Fix Is a Physical Switch on the Front of the Controller.
Tenable's mid-2026 write-up on CyberAv3ngers contains one line that changes how you should read this group. Alongside the familiar material — IOCONTROL, the water utilities, the joint advisory — they note exploitation of [CVE-2021-22681](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2021-22681). That CVE is from 2021. It carries a CVSS of 10.0. And CISA only added it to the Known Exploited Vulnerabilities catalog on 5 March 2026 — five years after disclosure. W
Patrick Duggan
Aug 25 min read


How to OSINT-Hunt a Nation-State With a Corpus You Already Have: The Vector Index, the Keyword Index, and the Six Ways the Count Lies to You
This started with a traffic anomaly, not a threat feed. Somebody was walking our search API one IP address at a time — 185.82.73.162, then .164, then .165, .167, .168, .171, .175 — over about twenty hours, one query each. That is not how a human searches and it is not how a scanner searches. It is how somebody with a list in front of them checks the list. The list turned out to be Iranian OT attack infrastructure. This post is the walk from anomaly to attribution to the parts
Patrick Duggan
Aug 29 min read


Three Coding Agents, One Comment, All Three Leaked Their Own Keys. One Vendor Called It 9.4 Critical, Paid $100, Then Downgraded It to None.
We hold that the interesting question about prompt injection is never does it work. It is which agent held. We report that flat in both directions — when one resists, we say so by name; when one folds, same. So here is the flat version. Aonan Guan, with Zhengyu Liu and Gavin Zhong of Johns Hopkins, pointed one class of injection at Anthropic's Claude Code Security Review, Google's Gemini CLI Action, and GitHub's Copilot Agent. None of the three held. All three leaked their ow
Patrick Duggan
Aug 25 min read


A CVSS 10.0 in Adobe Campaign Classic Needs Nobody to Open Anything. It Has Been Patched Four Days and Almost Nobody Has Written About It.
Adobe shipped APSB26-114 on 29 July. Two vulnerabilities in Adobe Campaign Classic v7, both fixed in build 9397 → 9398, on Windows and Linux. The headline one is [CVE-2026-48449](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-48449). Incorrect authorization leading to arbitrary code execution. CVSS 10.0. No authentication. No user interaction. Adobe rated the patch Priority 1 — their highest urgency tier. Its companion, [CVE-2026-48448](https://analytics.du
Patrick Duggan
Aug 25 min read


Schneider's New Bug Needs an Engineer to Open a File. We Spent This Week Documenting Controllers That Publish the Engineer's Name.
CISA published ICSA-26-211-04 on 30 July: an out-of-bounds write in Schneider Electric IGSS, tracked as [CVE-2026-12927](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-12927). Importing a malicious CGF file into the IGSS Definition module can cause data loss or arbitrary code execution. Fixed in 18.0.0.26125. Reported by Schneider Electric and by Michael Heinzl. If that sounds familiar, it should. On 26 July we wrote about four out-of-bounds writes in Rockw
Patrick Duggan
Aug 14 min read
bottom of page