top of page

All Posts


The GPS Spoofer At Khmeimim Air Base Has Been Affecting Commercial Aviation For Years. Someone Searched Us For It Tonight. We Don't Cover Russian Electronic Warfare. Here's Why That's About To Change.
On May 9 someone hit our search endpoint with the single query Khmeimim against all our indexes. Total results: one — the search-queries log entry of that...
Patrick Duggan
May 124 min read


Capgemini Got Hit Twice In Eighteen Months While Sitting Inside Their Clients' Networks. We Don't Have A Capgemini Post Yet. This Is The Receipt And The Gap.
Someone hit our blog search endpoint on May 11 with the query capgemini and got zero results.
Patrick Duggan
May 124 min read


Healthcare Sector Threat Intelligence, Indexed. Sixteen Posts, Five Operators, Every Brand In Your May 8 Watch List Found. The Zero-Result Bridge.
On May 8 a single IP hit our IOC search endpoint with fifty queries against named healthcare and education brands. Medtronic, Stryker, Kaiser Permanente,...
Patrick Duggan
May 124 min read


CVE-2026-7458: A WordPress Plugin Authenticates You As Anyone Who Submits 'true' For The OTP. PHP Loose Comparison Strikes Again. Second WP Plugin 9.8 In Five Days.
There is a WordPress plugin called User Verification by PickPlugins. As of May 2, 2026, every version through 2.0.46 contains an authentication bypass that...
Patrick Duggan
May 124 min read


Eight Posts on Iran's ICS War, Indexed. We Found You in Our Zero-Result Queue and This Is What You Were Looking For.
Someone hit our search endpoint this afternoon with the query iranian apt plc critical infrastructure 2026 and got zero results.
Patrick Duggan
May 125 min read


ShinyHunters Reset The Canvas Deadline. 'Data Destroyed' Lasted Forty-Eight Hours. Our May 12 Hedge Has An Expiration Date Now.
On May 8 we published our ShinyHunters watch list — eight named environments with pre-staged infrastructure including GE Healthcare, Moderna, and Nike. On...
Patrick Duggan
May 124 min read


Mini Shai-Hulud Hit npm May 11. We Indexed The Variant April 29. Canvas Paid May 11. We Named The Watch List May 8. Two More For The Ledger.
On May 11 at 19:20 UTC, the Mini Shai-Hulud worm pushed 84 malicious artifacts across 42 @tanstack/ packages, plus @uipath/ and @mistralai/mistralai. The...
Patrick Duggan
May 124 min read


Twenty-Eight Kittens: CISA Named Three Iranian Operators in AA26-097A. We've Been Indexing the Other Twenty-Five.
CISA dropped advisory AA26-097A this month, naming Iranian-affiliated APT activity targeting programmable logic controllers across United States critical infrastructure since at least March 2026. Water and wastewater systems. Energy. Government services. The advisory cites a small set of operator clusters by name and walks through the tradecraft — abuse of internet-exposed PLCs, credential reuse, lateral movement into industrial control plant networks. We have been doing the
Patrick Duggan
May 116 min read


Box Elder Already Has Three Toxic-Dust Hotspots. Kevin O'Leary Just Got 40,000 Acres of the Third Approved.
Earlier this month the Box Elder County Commission, in northwestern Utah, voted to approve a 40,000-acre AI and cloud computing campus called Stratos. The project is backed by O'Leary Digital and personally championed by Kevin O'Leary. It would consume up to 9 gigawatts of power, roughly double the electricity the entire state of Utah uses today. Power would be drawn from a connection to the Ruby Pipeline, a 680-mile interstate natural gas line. The land area is 2.5 times the
Patrick Duggan
May 116 min read


We Shipped a Tiny Free Tool That Tells You if an IP Is Bad. It's Also an AI Plugin Now. Here's What That Means.
Open a terminal. Type npx dugganusa-cli 185.39.19.176 and hit enter. You get back an answer. The IP is a known Cobalt Strike command-and-control server. We have blocked it forty-seven times. Three different threat-intel feeds have it on a list. There is a link to the full report. That is what we shipped today. A tiny free tool. No install. No signup. One command, one answer. We call it dugganusa-cli. It is also something else, but we will get to that. The everyday version Mos
Patrick Duggan
May 105 min read


Cushman & Wakefield Broke Our Salesforce-Okta Filter. None of the Predicted Ten Have Hit. Re-Rank Inside.
On April 26 we published "ShinyHunters Hit Six Companies in Seven Days. Here Are Ten Salesforce-Plus-Okta Targets That Fit Their Pattern." Two weeks later, the receipts say two things at once. Our filter caught real victims. Our filter was also too narrow. This is the public re-rank. The original ten, in fit-order T-Mobile. Verizon. American Express. Comcast and Xfinity. Chick-fil-A. Dollar General. Coca-Cola. JetBlue. Spotify. Target. The fit criteria we used were consumer-f
Patrick Duggan
May 104 min read


45 Days Early on LiteLLM. 20 Days Early on NGINX-UI. CISA Caught Up Today.
CISA added CVE-2026-42208 — the BerriAI LiteLLM SQL injection — to the Known Exploited Vulnerabilities catalog on May 8. CVSS 9.8. Federal agencies have until May 29 to patch it. We indexed LiteLLM C2 infrastructure on March 30. We named LiteLLM as compromised on March 24. We named NGINX-UI as actively exploited on April 20. This is the quantified ledger. The math is uncomfortable. The receipts, in order March 19, 2026. TeamPCP poisoned 76 of 77 release tags in Aqua Security'
Patrick Duggan
May 104 min read


Copy Fail: The Optimization Was The Cover-Up
CVE-2026-31431 — Copy Fail — was added to the CISA KEV catalog on May 1, 2026 with a federal-civilian remediation deadline of May 15. CVSS 7.8. Local-user to root on every major Linux distribution. A 732-byte Python script is the exploit. There is nothing exotic about it. It's a logic bug in the AEAD socket interface of the kernel's userspace crypto API (algif_aead in the AF_ALG subsystem), and it has been there since 2017. That last fact is the story. Nine Years In The Tree
Patrick Duggan
May 104 min read


🔺 Vol. 48: The Curation Is The Cover-Up
🔺 CONSPIRACY THEORY 🔺 The Newsletter They Don't Want You To Read Volume 48 | May 9, 2026 | $2.00 (cash only, no tracking) ――――――――――――――――――――― ATTENTION SUBSCRIBERS: If you opened the war.gov/UFO page this week, you're already on a list. Pentagon analytics. AARO logging. The same five-letter agencies that "didn't see anything for sixty years" suddenly know exactly which IP downloaded which JPEG. The transparency goes one way. ――――――――――――――――――――― THIS WEEK'S PATTERN: THE
Patrick Duggan
May 98 min read


JDownloader Got Compromised May 6 at 00:01 UTC. The Day Before Our Hunt-Tonight Cadence. Researchers Pulling Our Drops Got a Python RAT Bonus.
May 9, 2026 · DugganUSA LLC JDownloader is the bulk-download tool of choice when you want a whole archive at once. Researchers use it. Journalists use it. Threat-intelligence analysts use it. Anyone pulling a multi-file evidence set from a release page is, with high probability, running JDownloader to do it. JDownloader's official website was compromised between May 6, 2026 at 00:01 UTC and detection on May 7, 2026. A little over twenty-four hours of silent installer swapping
Patrick Duggan
May 96 min read


Hard Perimeter Holds. Soft Surfaces Bleed. Seven Receipts From Thirty Days.
The standard threat-intel headline reads "Company X got breached." It's almost never true. The hard perimeter — auth, ingress, core systems, EDR, the things...
Patrick Duggan
May 95 min read


TeamPCP Just Took Out OpenAI's macOS Code-Signing Certificate. We've Been Tracking This Crew Since March.
OpenAI revoked their macOS desktop application code-signing certificate as a precaution. Effective yesterday, May 8, 2026, older versions of the OpenAI...
Patrick Duggan
May 94 min read


713 IOCs Tied to Actively-Exploited CVEs in Our Index. Patch These First.
We just closed an attribution gap in our threat-intel index. Until today, only one of the 1.14 million IOCs in our iocs index had a CVE attached. Tonight,...
Patrick Duggan
May 97 min read


We Ran the Pentagon's UFO Drop Through a 20-Point PsyOps Framework. The Score: 69 Out of 95.
The Pentagon's PURSUE Release 1 dropped on Friday May 8, 2026. War.gov/UFO. Department of War. AARO. ODNI, DOE, NASA, FBI listed as participating. Press...
Patrick Duggan
May 98 min read


Iran's Two Cyber Wings Are Running ICS Campaigns at the Same Time. CISA Just Confirmed It.
We have 60-plus published posts on the Handala Hack Team and the broader Iran-aligned cyber lineage. We have an indicator-of-compromise database that...
Patrick Duggan
May 96 min read
bottom of page