top of page

All Posts


Qilin Is Now Riding a Palo Alto VPN Auth-Bypass Into Corporate Networks. The Patch Shipped in May. The Ransomware Didn't Wait.
There is a particular kind of security failure that keeps producing ransomware incidents, and it is not the unpatched zero-day. It is the patched bug that everyone was too slow to apply. Palo Alto's GlobalProtect flaw CVE-2026-0257 is now the entry point for Qilin ransomware, and the timeline is the whole indictment: the fix has existed since May. What the bug is CVE-2026-0257 is an authentication bypass in Palo Alto's PAN-OS GlobalProtect portal and gateway — the VPN front d
Patrick Duggan
Jul 214 min read


This macOS Malware Kills Every App on Your Screen Every 210 Milliseconds Until You Type Your Password. It's Called ClickLock, and It Works Because You'll Do Anything to Make It Stop.
Most malware wants to stay invisible. ClickLock does the opposite. It makes itself the only thing you can see, and it makes your Mac unusable on purpose, because a person who cannot open a single application will type their password into almost anything that promises to give their computer back. The technique is coercion, not stealth Here is what ClickLock actually does once it's running on a Mac. It kills every visible application, at intervals of roughly 210 milliseconds —
Patrick Duggan
Jul 214 min read


Two Different Crews Breached Abbott the Same Week — a Cancer-Diagnostics Unit and a Lab Portal. In March We Said Medical-Device Makers Were the Ones Getting Breached. Abbott Is the Receipt.
Abbott Laboratories is dealing with two cyberattacks at once, from two unrelated crews, hitting two different parts of the company in the same window. That is unusual enough to note on its own. What makes it worth a full write-up is that we called this category — out loud, in March — and Abbott is the receipt. Two breaches, two actors, one building The first intrusion hit Abbott's Cancer Diagnostics business, specifically legacy systems from Exact Sciences, a company Abbott a
Patrick Duggan
Jul 215 min read


A Week After LegacyHive Dropped, Microsoft Still Hasn't Patched It. A Third Party Did — For Free. Here's the Honest Read on the Windows Zero-Day.
On July 14, Microsoft closed 570 vulnerabilities — its largest Patch Tuesday ever, two of them already exploited in the wild. Hours later, a researcher known as Nightmare Eclipse (also seen as Chaotic Eclipse, and known around Redmond as a serial tormentor) published a working proof-of-concept for a Windows flaw with no CVE, no advisory, and no security update. It is called LegacyHive, it affects fully patched machines, and a week on, Microsoft still has not shipped a fix. So
Patrick Duggan
Jul 214 min read


Four AI Coding Agents Got Their Sandboxes Broken This Week — and Nobody Attacked the Sandbox. They Just Wrote a File the Grown-Ups Outside Trusted.
The security model of an AI coding agent rests on one promise: the agent runs in a sandbox, so even if it does something dangerous, the blast radius is contained. Pillar Security spent several months proving that promise hollow across four of the most widely used agents — Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity — and the way they did it is the part worth understanding, because it is not the way you would expect. They never attacked the sandbox. The escape
Patrick Duggan
Jul 214 min read


The First AI-Native Ransomware Is Here. It Doesn't Lock Your Files — It Encrypts the Models Themselves, and We've Been Blocking Its C2 Since Friday.
Ransomware has always gone after the same two things: your files and your uptime. Lock the documents, halt the servers, wait for the wire transfer. A new strain called ENCFORGE goes after something a company can't rebuild from a backup drive and can't buy back at any price — the trained AI models themselves. And the group behind it is one we've been tracking since it first appeared: JADEPUFFER, the first genuinely agentic threat actor. Sysdig documented the evolution this wee
Patrick Duggan
Jul 215 min read


Estée Lauder Just Confirmed It Was Breached in the Oracle Attack We Covered Last Fall. The Intruders Were Inside Eleven Months Ago — Before the Bug Was Even Public.
Estée Lauder has told the Vermont Attorney General that attackers broke into its Oracle E-Business Suite HR environment and stole employee data — names, Social Security numbers, and health information. This is not a new attack. It is a name finally attached to an old one, and the timeline is the whole story. The intruders got in on or around August 9, 2025. Estée Lauder disclosed it on July 10, 2026. Eleven months. And here is the part that should stop you: the vulnerability
Patrick Duggan
Jul 204 min read


WatchGuard Patched This Firewall Bug Nine Months Ago. Someone Just Tuned the Exploit to Your Exact Firmware Build.
Most people think an exploit has a moment. The vulnerability drops, the proof-of-concept lands, there is a scramble to patch, and then the story ends. It does not end. The patch ships and the exploit keeps getting better, quietly, for the machines that never applied the fix — and this week we watched a nine-month-old firewall bug get sharpened to a specific firmware build. The bug, and its already-long history CVE-2025-9242 is an out-of-bounds write in the iked process of Wat
Patrick Duggan
Jul 205 min read


ServiceNow Holds the Map of Your Entire Network. A Pre-Auth Bug Just Handed It to Strangers, and the Patch Is Four Days Old.
Attackers do not break into ServiceNow for the ticketing. They break in for the map. A ServiceNow instance holds the CMDB — the configuration management database, which is the single most complete inventory of your infrastructure that exists anywhere in your company. Every server, every application, every dependency, who owns it, what it talks to, what breaks if it goes down. It is the thing a red team spends weeks reconstructing, sitting in one place, indexed and searchable.
Patrick Duggan
Jul 204 min read


This Iranian Malware Has No C2 Server to Block. The Command Channel Is a Meeting Invite in Your Own Calendar.
There is nothing to add to a blocklist here, and that is the entire point. Group-IB disclosed a piece of Iranian-nexus malware called HollowGraph that has no command-and-control server. Not a hidden one, not a fast-flux one — none. It never sends a packet to attacker infrastructure. It reads its orders out of, and writes its stolen data back into, the victim's own Microsoft 365 calendar, over the legitimate Microsoft Graph API, using the victim's own credentials. The operator
Patrick Duggan
Jul 205 min read


GitHub Had a Valid Replacement Certificate for 31 Days Before the One It Was Serving Expired. The Renewal Never Failed. The Rollout Did.
Last night we wrote that GitHub let a Let's Encrypt certificate expire and took every self-hosted Actions runner offline worldwide. That was accurate. Our explanation of why was not, and Certificate Transparency logs have the receipt. No certificate was issued during the outage We pulled the full issuance history for actions.githubusercontent.com. There is no certificate issued on July 19 or July 20. Nothing during the incident at all. What the logs show instead is a renewal
Patrick Duggan
Jul 205 min read


An AI Agent Breached Hugging Face. When the Defenders Asked an AI for Help Reading the Logs, They Were Refused.
Hugging Face disclosed on July 16 that an autonomous AI agent breached its production infrastructure. It is the first publicly confirmed end-to-end agentic intrusion against an AI infrastructure provider, and by itself that would be the story. It isn't the story. This is, and it's four paragraphs down in their own disclosure: When Hugging Face's responders tried to use frontier models behind commercial APIs to analyze the attack logs, the requests were blocked by the provider
Patrick Duggan
Jul 205 min read


A Seven-Year-Old RubyGem Is Trusted By Design. SleeperGem Turned That Into the Attack, and Our Own Scanner Said Allow.
Three malicious gems went up on RubyGems this weekend. Two of them came from real maintainer accounts that had been sitting quietly since 2019 and 2020. That dormancy was not incidental to the attack. It was the attack. We publish a package-reputation scanner. I ran it against those gems this morning. It said allow. Here is what happened, why our detector was wrong, and what it does now. What SleeperGem is Researchers at StepSecurity and Aikido Security disclosed a Ruby-ecosy
Patrick Duggan
Jul 207 min read


GitHub Let a Free Certificate Expire and Killed Every Self-Hosted Runner on Earth
At 23:05:54 UTC tonight, a Let's Encrypt wildcard certificate reached the end of its 90-day life and every self-hosted GitHub Actions runner on the planet stopped taking jobs at the same second. Matt Lucas at RedEye Security root-caused it publicly eleven minutes before GitHub's status page said a word. His write-up is here and it is correct end to end: GitHub Actions Cert Expiry and the Self-Hosted Runner Outage. We are not claiming this one. We confirmed it independently, f
Patrick Duggan
Jul 196 min read


We Claimed a Two-Month Lead. Our Own Timestamp Says We Were One Day Late.
On July 16 we published a post with this headline: the FamousSparrow command-and-control server was in our feed since May 14, two months before the report named it. That is wrong, and the evidence that proves it wrong is our own database record. What the record actually says The indicator is a typosquatted SentinelOne domain used as a hard-coded Deed RAT C2 in the FamousSparrow intrusion into Azerbaijani oil and gas. Our record for it carries three fields that settle the ques
Patrick Duggan
Jul 194 min read


The Attacker Did 11% of the Work. Gemini Did the Rest. The Victim Was a Dental Clinic.
A criminal operating as bandcampro ran more than two hundred sessions against Google's Gemini CLI and used it as his primary hacking tool. Trend Micro reconstructed the operation and the arithmetic is the part worth sitting with. The human did eleven percent of the work. The AI did the rest, and on fifty-nine separate occasions it proposed operational improvements nobody asked it for. When a command-and-control server needed to move, the migration took six minutes. The victim
Patrick Duggan
Jul 194 min read


Why Enterprise Security Fails - and How To Fix That
Our production service signed every session cookie with a hardcoded string. Not a weak secret. A literal, printed in the source file, sitting in a public-facing authentication path. Anyone who could read that file could forge an authenticated session for the admin dashboard. It had been that way for months. Logins worked. Sessions persisted. Uptime was green. Every dashboard we own said the service was healthy, because by every measure we had, it was. We found it in one day,
Patrick Duggan
Jul 199 min read


Grep Found Nothing. The MCP Found Seven.
We spent a day pointing our own security tooling at ourselves. It found seven things. The most serious one had been sitting in production for months, and every dashboard we own said it was fine. Here is what broke, why grep would never have caught it, and how to run the same method against your own stack in about two minutes. The one that mattered Our analytics service signs session cookies with a secret pulled from Azure Key Vault. That is the correct design. The code fetche
Patrick Duggan
Jul 195 min read


A Hacker Left His Server Open for 22 Days. Inside: 1.4 Million WordPress Targets, 27 Weaponized CVEs, and a Webshell Kit Called WP-SHELLSTORM.
The best threat intelligence of the weekend did not come from a vendor's telemetry or a honeypot. It came from an attacker who forgot to close a door. Someone running a professional WordPress mass-compromise operation stood up a plain Python SimpleHTTPServer to move files around, and left it facing the internet for twenty-two days. Researchers found it, and inside was the entire business: the toolkit, the logs, the target lists, and the receipts. The operation has a name now
Patrick Duggan
Jul 194 min read


APT28 Deleted the Payload. A Worm Deleted the Operator. OIDC Deleted the Password. That's One Pattern.
Security tools are built to catch a thing. Antivirus catches a payload. Secret-scanning catches a credential. Behavioral analytics catches an operator — a human doing human-shaped work at human-shaped hours. Every one of those defenses is an assumption wearing a product badge: it assumes the thing it looks for is present to be found. The most interesting attacks of the last twelve months have a single move in common, and once you see it you cannot unsee it. They win by deleti
Patrick Duggan
Jul 196 min read
bottom of page