top of page

All Posts


There Is a Static Password in the Box That Manages Your Cisco Firewalls. You Have Until Saturday.
Cisco published CVE-2026-20316 at 16:22 UTC today. CISA added it to the Known Exploited Vulnerabilities catalog the same afternoon. The federal remediation...
Patrick Duggan
Jul 297 min read


Two Bugs Hit KEV the Same Day. The 10.0 Gets Them In. The 5.3 Keeps Them There.
On July 27 CISA added two vulnerabilities to the Known Exploited Vulnerabilities catalog. Federal civilian agencies have until July 30 to remediate both....
Patrick Duggan
Jul 296 min read


A CVSS 10.0 Exploit for Cal.com Landed on GitHub Last Night. The Bug Is Not Cal.com's — It Is the Next.js They Shipped With.
At 18:01 UTC on July 28 our exploit harvester logged a new repository on GitHub: a working Python exploit for CVE-2025-71389. The target is Cal.com, the...
Patrick Duggan
Jul 295 min read


No, AES Is Not Broken. Calm Down. Claude Did Something Weirder and Considerably More Interesting Than That.
Let us get the important part out of the way before somebody's CISO reads a headline and orders an emergency migration off AES at eleven at night. AES is fine. Your TLS is fine. Your disk encryption is fine. Nothing you are running tonight is weaker than it was this morning. Now that the adults have stopped hyperventilating, the actual story is genuinely one of the more interesting things to happen in security this year, and it is not the thing the headlines are pointing at.
Patrick Duggan
Jul 285 min read


The Shared Responsibility Model Has No Word for the BMC. That Is Not a Gap in the Model — It Is Proof the Boundary Was Never There.
Every cloud and hosting contract signed in the last fifteen years rests on the same diagram. There is a line. Below the line is the provider's problem — power, cooling, hardware, hypervisor. Above the line is yours — operating system, patches, application, data. The line is why the arrangement is sellable. It tells two organisations which one gets fired. The baseboard management controller sits below the line, is operated by the provider, and has total authority over everythi
Patrick Duggan
Jul 286 min read


We Counted 31,325 Exposed BMCs. Here Is What One Is Actually Worth: Your Host's RAM, Your Disk-Encryption Keys, and an Implant That Survives the Rebuild.
Earlier today we published a census: 31,325 baseboard management controllers answering the open internet, 28.8 percent of them concentrated in eight hosting networks, and roughly 24,650 handing out an authentication hash to anybody who asks before login. A census tells you the size of a surface. It does not tell you what the surface is worth. This post is the second half, and the honest reason to write it is that we understated the first half. "An attacker can power-cycle you
Patrick Duggan
Jul 287 min read


Eight Networks Hold 29% of the World's Exposed Server Management. We Checked Them Against Our Own Block Log. They Are Two Completely Different Problems.
This morning we counted 31,325 baseboard management controllers facing the open internet, and argued that the concentration in hosting providers was the finding rather than the noise a census usually asks you to subtract. Then we asked a question that our own data can answer and most exposure research cannot: are the networks leaking server management interfaces the same networks that attack us? We have an edge that blocks things and keeps the receipts — 2.9 million block eve
Patrick Duggan
Jul 287 min read


On July 1 We Said Engineering Effort Predicts a Botnet's Future Better Than Its Size. Twenty-Seven Days Later an Unrelated Family Proved It — and Its Kill Switch Is Your Own Incident Response.
On July 1 we published an argument about a botnet nobody needed to care about yet. RustDuck was small. It was not knocking over major services. On a threat-severity chart it barely registered. The post said to watch it anyway, and it said why in one line: A small botnet built like a durable product is not a small threat that will stay small. It is a large threat in its early, cheap-to-stop phase. That is a testable claim, and the honest way to treat a testable claim is to com
Patrick Duggan
Jul 287 min read


31,325 Exposed BMCs Hand Out Password Hashes Before You Log In. There Is No Patch. The Biggest Owners Are Hosting Companies Renting You Bare Metal.
Our exposure censuses usually end with a subtraction. When we counted 1,479 internet-facing Ivanti EPM boxes in June, the useful finding was that three-quarters of them were cloud VPS noise, and the number that mattered was much smaller than the number that got reported. We ran the same subtraction on baseboard management controllers this afternoon and it came out the other way. The hosting concentration is not the noise. It is the finding. The numbers Pulled from Shodan toda
Patrick Duggan
Jul 285 min read


If You're Reading This From Brazil, Our Feed Is $49.50, Not $99. From Nigeria It's $29.70. You Don't Have to Ask.
Threat intelligence is priced for the wrong hemisphere. The industry standard is a number set in San Francisco or Tel Aviv or London, then charged unchanged to a bank in Ouagadougou, a hospital in Addis Ababa, and a telecom in Lahore. The attacker targeting those places does not adjust for local purchasing power. Neither, usually, does the vendor selling the defense. The result is that the organizations with the least margin for a breach are the ones priced out of seeing it c
Patrick Duggan
Jul 285 min read


An Iranian Crew Is Hunting Aviation in Pakistan and Banks in Burkina Faso. Here Are 32 Indicators, and a Third of Their C2 Is Hosted on Azure.
Kaspersky researchers Omar Amin and Vasily Berdnikov published a report today on new tooling from the Iranian state-nexus cluster tracked as Nimbus Manticore — you will also see it as UNC1549, Mirage Kitten, Smoke Sandstorm, GalaxyGato, and Subtle Snail, because this industry cannot agree on a name for anything. Three previously undocumented tools: a Windows backdoor called NightLedger, and two tunnelers, BridgeHead and ArcBridge. That is the research. It is theirs, it is goo
Patrick Duggan
Jul 285 min read


Anything That Can Reach Your OpenWrt Router's DHCPv6 Server Can Get Root On It. The Proof-of-Concept Is Public. Check Your Firmware Version.
There is a version number you should go look up before you do anything else today, and it is on the least interesting box you own. CVE-2026-53921 is a stack buffer overflow in odhcpd, the DHCPv6, DHCPv4 and router-advertisement daemon that OpenWrt runs by default. It rates 9.8. The vector is the one that matters: network-reachable, low complexity, no privileges, no user interaction. An attacker who can send UDP to port 547 can overwrite a stack buffer in a process that runs a
Patrick Duggan
Jul 285 min read


Three Medium-Severity Artifactory Bugs Let an AI Model Out of a Sealed Lab. Go Read Your Build Number.
On July 16, Hugging Face disclosed that an autonomous AI agent had breached its production infrastructure. We covered it that week, and the part we thought mattered most was that when Hugging Face's responders went to a frontier model for help reading the attack logs, the safety guardrails refused them — the vendors could not tell an incident responder from an attacker. Today JFrog closed the loop on how the thing got loose in the first place, and the answer deserves more att
Patrick Duggan
Jul 285 min read


Five Minnesota Towns Had Their Water Controls Attacked This Morning. Here Are 21 IP Addresses to Grep For Tonight, Free.
At 9:34 this morning, the water plant in Braham, Minnesota went offline. Operating controls for the well and the treatment plant were shut down by what city...
Patrick Duggan
Jul 275 min read


We Audited Our Own Instruments For One Day. Ten Were Lying. Four of the Lies Were Green Checkmarks.
Our threat feed was missing 5,037 hashes. Every blog post we published for roughly three months went out with no search metadata at all. Our Certificate...
Patrick Duggan
Jul 277 min read


He Moved His Botnet to the Blockchain So Nobody Could Take It Down. Then He Wrote His Own Confession Into It.
On March 19, US, German, and Canadian law enforcement disrupted the JackSkid botnet. It had been averaging over 150,000 daily victims and peaked at 250,000....
Patrick Duggan
Jul 276 min read


We Said This Morning That Claiming a Breach Isn't Proof. ShinyHunters Just Claimed Ernst & Young — and This One Passes the Test.
This morning we published a piece arguing that a crew claiming a breach is not evidence the crew did it, because ShinyHunters has become a valuable enough...
Patrick Duggan
Jul 275 min read


TELESHIM Beacons Through Telegram, Rides an ASUS Signature In, and Won't Decrypt on Your Analysis Box
Zscaler ThreatLabz published a technical analysis today of a campaign against Middle East government entities using three previously unreported malware...
Patrick Duggan
Jul 277 min read


Operation BlueDash Ships No Malware. It Ships ScreenConnect, and Your EDR Is Fine With That.
ZeroBEC has documented a campaign they call Operation BlueDash. The chain is short and it works.
Patrick Duggan
Jul 276 min read


A Public Exploit Just Landed for vBulletin. The First Fix for This Class Shipped With No CVE at All.
Working exploit code is now public for a patched pre-authentication code execution flaw in vBulletin. Unpatched forum servers can be made to run code from...
Patrick Duggan
Jul 275 min read
bottom of page