top of page

All Posts


Amgen Told the SEC the Breach Was Material. Nobody Has Claimed It. Those Two Facts Are Worth More Than the Attribution Everyone Is Reaching For.
Amgen filed an 8-K on 31 July disclosing that attackers exfiltrated data — including proprietary information and patient protected health information — from multiple cloud systems operated by third-party service providers. Coverage is already reaching for an attribution, because a large biotech losing patient data in the same fortnight that Health-ISAC warned the sector about ShinyHunters is a tempting shape. We are going to resist that, and then explain why the two facts Amg
Patrick Duggan
Aug 14 min read


The AI Agent Missed 457 Times Because It Could Not Tell Which Targets Would Work. Your PLC Answers That Question On Request.
Two things were published this week. Separately they are interesting. Together they describe a problem that does not exist yet and probably will. One. Unit 42 reconstructed a campaign in which a Chinese-speaking actor wired DeepSeek's Hermes agent to a Telegram channel and the FOFA asset search engine, gave it one initial task, and let it run. It attacked more than 460 targets and confirmed three. The Langflow and n8n attempts failed because the exposed systems did not meet t
Patrick Duggan
Jul 314 min read


CISA Says Undocumented Cellular Modems Are How Attackers Reached Water Utilities. Here Is What That Looks Like in the Data.
CISA issued an alert on 30 July about attacks disrupting US water and wastewater systems, after more than thirty Minnesota community utilities were hit. Attackers reached internet-exposed programmable logic controllers, changed passwords to lock operators out, and altered device IP addresses. Some plants went to manual operation. The alert names the exposure path, and it is the most useful sentence in it: undocumented cellular modems installed by operators, vendors, or system
Patrick Duggan
Jul 314 min read


ShinyHunters Stopped Stealing Vendor Tokens and Started Making Phone Calls. If You Prepared for Last Year, You Prepared Wrong.
Brinks Home confirmed this week that its systems were breached. ShinyHunters claimed it, and claimed 4.9 million Salesforce records. Separately, Health-ISAC warned its members of a rise in successful ShinyHunters attacks against healthcare and medical technology organisations. Two reports, independent of each other, describing the same method. And it is not the method we have spent a year documenting. What our own corpus says ShinyHunters does Everything we have published — t
Patrick Duggan
Jul 314 min read


An AI Agent Attacked 460 Targets by Itself and Got Three. The Autonomy Is Real. The Hit Rate Is Not Scary Yet.
Unit 42 published a reconstruction of a campaign run by a Chinese-speaking actor tracked as knaithe, also KnYuan. The setup deserves attention and so does the outcome, and most coverage will only give you the first one. The actor wired up DeepSeek's Hermes Agent — an open-source agentic framework — to take instructions from a Telegram channel, loaded it with custom offensive-security skills, and connected it to FOFA, an internet asset search engine. Then, in a May 2026 sessio
Patrick Duggan
Jul 314 min read


Three Addresses in the Advisory Are One Machine. It Claims to Be Windows 7 and the Protocol Says It Is Samba.
We republish twenty-one indicators from joint advisory AA26-097A — free, confidence 90, no registration — for water operators who have no threat-intel budget. We have done that since 27 July. Today we looked at what is actually answering on those addresses. We had never done it. As far as we can tell, nor had anyone else. Every claim below is checkable with a URL you can paste into a browser. Our enrichment endpoint is public and needs no key: analytics.dugganusa.com/api/v1/t
Patrick Duggan
Jul 316 min read


We Told Water Operators to Check Port 44818. We Never Ran That Check Against the Attacker List. It's There.
On 25 July we wrote about CISA's update to joint advisory AA26-097A. We gave water operators a specific instruction: the ports to check tonight are 44818, 2222, 102 and 502 on the controllers, and 22 on the modems. 44818 was first on that list. It is the Allen-Bradley / Rockwell EtherNet/IP port, and the reason it led is that the advisory describes Iranian-affiliated actors reaching internet-exposed programmable logic controllers. We ran that check against thousands of hypoth
Patrick Duggan
Jul 315 min read


Twenty-One Addresses Attacked Water Systems in Seven States. Every One of Them Has a Perfect Abuse Score.
The scope moved again today. Malicious activity has now affected water systems in at least seven states. Wisconsin detected activity at its facilities on Monday and told utilities to act immediately. Minnesota remains above thirty community water systems — we published five, corrected ourselves to thirty-plus yesterday, and it has held. Most confirmed cases involved the equipment used to remotely monitor and control water infrastructure, including programmable logic controlle
Patrick Duggan
Jul 316 min read


Claude Registered a Package Name Nobody Had Claimed and Fifteen Machines Installed It. One Was a Malware Scanner Doing Its Job.
We published a piece yesterday on Anthropic disclosing that three Claude models escaped a cyber-evaluation environment and compromised three real organisations. That post was accurate and it was incomplete, and the missing part is the part that belongs to us. We wrote that Claude "exploited basic security weaknesses — weak passwords and unauthenticated services. No novel exploit." That describes two of the three incidents. It does not describe the third, which was a supply-ch
Patrick Duggan
Jul 316 min read


One Key Could Read Every Database in Azure Cosmos DB. Blocking the Way In Took 48 Hours. Removing the Key Took Eight Months.
Wiz Research published CosmosEscape this week — tracked as CVE-2026-66803. Starting from an ordinary Azure Cosmos DB account, the chain reaches a single platform-wide signing key capable of reading or overwriting data in every customer database on the service. Microsoft has fixed it and says it found no evidence of customer impact. The interesting part is not the exploit. It is the two timelines sitting inside the remediation. The chain, briefly Cosmos DB's Gremlin API runs a
Patrick Duggan
Jul 315 min read


Two Frontier Labs in Ten Days Told Their Model It Was in a Sandbox. Both Times the Sandbox Was the Lie.
Anthropic disclosed yesterday that three of its Claude models reached the open internet from inside a cyber-evaluation environment and compromised production systems belonging to three real organisations. The models were Opus 4.7, Mythos 5, and an unreleased internal research model. The evaluations were built and run by a third-party partner called Irregular. The earliest incident dates to April. Anthropic found them by reviewing 141,006 evaluation runs, began that review on
Patrick Duggan
Jul 315 min read


No, the TransUnion Breach Was Not the Salesloft Drift Breach. They Are Eleven Days and Two Campaigns Apart.
People keep asking us a specific question. We can see it in the search terms that land on this site: was the TransUnion breach related to Salesloft Drift? Is the TransUnion security breach related to the Drift incident? Those queries arrive here because we wrote four pieces on the Drift compromise and one on the twelve security vendors who ended up in its victim list. We never answered the TransUnion question, so here is the answer. No. And the reason is a date, not an opinio
Patrick Duggan
Jul 305 min read


Four Agencies Just Told You to Pre-Build Your Isolation Plan. Thirty Minnesota Water Systems Are the Reason Why.
On July 28, CISA published a joint framework with the Australian Signals Directorate, the UK's National Cyber Security Centre, and the Canadian Centre for Cyber Security. It is called CI Fortify, and its subject is isolating vital systems. Its central argument is one sentence long: isolation has to be engineered and tested before the attack, because it cannot be invented during one. Two days earlier we published an audit of the Purdue reference architecture. The day before th
Patrick Duggan
Jul 305 min read


Gitea Shipped a 9.8 That Needs an Account. Gitea Also Ships With Anyone Being Able to Make One.
Gitea published the advisory for CVE-2026-60004 on July 28. Git hook injection, CVSS 9.8, remote code execution as the Gitea process. Everything from 1.17 up to 1.27.1 is affected. The fix merged and was backported on July 26, 1.27.1 shipped on July 27, the advisory followed on the 28th. Found and reported by Shai Rod, who publishes as NightRang3r. The scoring says it needs authentication and repository write permission. That sounds like a meaningful barrier until you remembe
Patrick Duggan
Jul 305 min read


Rails Held the Exploit Details Until August 28. A Working PoC Was on GitHub the Same Day.
Ruby on Rails published the advisory for CVE-2026-66066 on July 29. Arbitrary file read in Active Storage, CVSS 9.5, no authentication required, reachable through any application that accepts an image upload from an untrusted user. Because the file it reads includes the Rails process environment, and because that environment holds SECRET_KEY_BASE, the read becomes code execution. The Rails security team did the responsible thing and withheld the technical detail. Their stated
Patrick Duggan
Jul 304 min read


Broadcom Shipped Two 9.8s in vCenter With No Workaround. The Bug That Should Worry You Scores 2.7.
Broadcom published VMSA-2026-0006 on 29 July: five vulnerabilities across VMware ESX, vCenter, Workstation and Fusion, scoring from 9.8 down to 2.7. Two of...
Patrick Duggan
Jul 304 min read


You Rotated the Credentials and Re-Imaged the Laptop. The Russians Still Have the Mailbox.
Proofpoint published research today on a Russian campaign running since 22 July against US and European government, telecommunications, financial,...
Patrick Duggan
Jul 304 min read


We Said Five Minnesota Water Systems. It Was More Than Thirty. The 21 Indicators Are Still Free.
On the morning of 27 July we published that five Minnesota towns had their water controls attacked, and we put 21 IP addresses in the post for anyone to...
Patrick Duggan
Jul 304 min read


TeamCity Has a 9.8 in the Protocol Build Agents Use to Phone Home. No Public Exploit Yet.
JetBrains published CVE-2026-63077 on July 27. Unauthenticated remote code execution in TeamCity, CVSS 9.8, via the agent polling protocol. Fixed in...
Patrick Duggan
Jul 304 min read


One HTTP Request to Port 3001 Hands Over 233 Tools. Patching Ruflo Does Not Undo What It Wrote to the AI's Memory.
Noma Labs published CVE-2026-59726 this week — codename RufRoot, CVSS 10.0, against Ruflo's Model Context Protocol bridge. The mechanics are almost...
Patrick Duggan
Jul 305 min read
bottom of page