top of page

All Posts


Everest Hit Coca-Cola Twice. The Middle East Passports in the Fairlife Leak Are the Fingerprint.
On July 16, Coca-Cola told the world that its Fairlife dairy unit had stopped making milk in the United States. The wording in the disclosure was the careful kind: an unauthorized third party reached "a portion" of its systems, production-related systems included, the investigation is ongoing, product safety was not affected, law enforcement is notified. No gang was named. No terabytes were counted. It read like every other breach notice — the corporate shrug you learn to ski
Patrick Duggan
Jul 194 min read


Salt Typhoon's Official Advisory Lists 88 Indicators. You Can Block Exactly None of Them.
We spent the afternoon auditing our own threat coverage — going actor by actor through the groups we track, counting how many hard indicators we actually have attributed to each one. The plan was housekeeping: find the gaps, fill them, move on. Instead we found the floor under the entire indicator-feed industry, and it is not where anybody advertises it. If you run a SOC and you are in a hurry, here is the short version: the indicators worth having are already live in our fre
Patrick Duggan
Jul 185 min read


We Said Get Splunk Off the Internet. Shodan Says 11,422 of You Didn't — and 6,900 Are in the United States.
Yesterday we wrote up CVE-2026-20253, a CVSS 9.8 flaw in Splunk Enterprise tracked in Splunk's own advisory SVD-2026-0603. The root cause is the plainest kind there is: a PostgreSQL sidecar service endpoint that ships with no authentication at all, classified CWE-306, missing authentication for a critical function. Any network-reachable stranger can invoke it to create or truncate arbitrary files on the box, and public research has shown the primitive chaining into pre-authen
Patrick Duggan
Jul 183 min read


A Cyberattack Stopped Japan's Biggest Frozen-Food Company Cold, and KFC Japan Ran Short of Ingredients. The Freezer Is Critical Infrastructure Now.
On July 13, Nichirei, one of Japan's largest food companies and the backbone of its frozen-food logistics, suffered a cyberattack severe enough that the company pulled the plug on its own group systems to contain it. Disconnecting the network stopped the bleeding and also stopped the freezers-and-forklifts side of the business. Refrigerated warehouse operations and frozen-food shipments seized up. The knock-on landed somewhere most people would never connect to a server breac
Patrick Duggan
Jul 183 min read


NadMesh Is a Botnet Built to Hunt Your AI Tools. 20-Plus Exploits, 3,811 Stolen AWS Keys, and a Scan Queue Full of the Langflow and Ollama Boxes You Stood Up Fast and Firewalled Late.
For most of the past two years, attacks on the AI stack have been one-off events: a poisoned model here, a prompt injection there, a single compromised agent. NadMesh is the moment that stopped being artisanal. It is a Go-written botnet, disclosed in mid-July, that carries more than twenty remote code execution exploits and points every one of them at the same target class: the AI and MCP services that engineering teams spin up in an afternoon and get around to securing next
Patrick Duggan
Jul 183 min read


WordPress Shipped an Emergency Patch on a Friday for a Pre-Auth RCE in Its Own Core. It's Called wp2shell, It Needs No Login, and the Weekend Is the Exploit Window.
WordPress pushed emergency releases today, version 7.0.2 and 6.9.5, to close a pre-authentication remote code execution vulnerability in core. Researchers at Searchlight Cyber named it wp2shell, and it is tracked as CVE-2026-63030. No login, no plugins, no special configuration. A default WordPress install answers an anonymous HTTP request and runs the attacker's code. It shipped on a Friday, which is the part that should decide how you spend the next hour. What wp2shell actu
Patrick Duggan
Jul 173 min read


Three Perfect-10 Bugs in UniFi OS Are Being Exploited to Mint Rogue Admins. It's the Gear Half the Small Offices in America Run — and We Told You Its Clean Look Was Hiding Something.
Ubiquiti's UniFi gear is everywhere. It runs the network in dentist offices, small law firms, coffee shops, church basements, and about half the home labs of everyone reading this. It is beloved because the interface is clean and it just works. Three vulnerabilities in UniFi OS now carry a CVSS score of 10.0 apiece, the maximum, and attackers are chaining them to create their own administrator accounts on other people's networks. CISA put all three on its Known Exploited Vuln
Patrick Duggan
Jul 173 min read


Splunk Enterprise Will Let an Unauthenticated Stranger Write Files to Your SIEM. It's Being Exploited Days After Disclosure. The Watchtower Has a Hole in the Floor.
Splunk is the tool a lot of security teams stare at all day. It ingests the logs, runs the detections, and is supposed to be the place you find out you were attacked. CVE-2026-20253 turns that around. It is a missing-authentication flaw in Splunk Enterprise that lets an attacker with no credentials at all create or truncate files on the system through a PostgreSQL sidecar service endpoint. CISA added it to the Known Exploited Vulnerabilities catalog, and it is being used in a
Patrick Duggan
Jul 173 min read


For the Folks Just Tuning In: Yes, Claude Helps Write This, and I'm Loud About It. Here's the Honest Deal.
More of you showed up this week than usual, so a quick hello and a plain explanation of what this place is, from the person who runs it. What this is This is threat intelligence from a small, independent shop in Minnesota. No venture money, no big team, no marketing department. One person and an AI partner, working the same feeds the billion-dollar vendors work, and publishing what we find. When something is exploited in the wild, when a supply-chain package goes bad, when an
Patrick Duggan
Jul 173 min read


FortiSandbox Is Back on CISA's Exploited List, and This Time Feds Get Four Days. We Started the Fortinet Clock in May. It Already Ran Out.
On July 15, CISA added two Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog and gave federal agencies until Sunday, July 19, to patch under Binding Operational Directive 26-04. Four days. FortiSandbox is the appliance that is supposed to detonate suspicious files in a safe container so they never reach your users. Two ways into it now let an unauthenticated attacker run code on the box itself. What the two flaws are Both are command-injecti
Patrick Duggan
Jul 173 min read


Microsoft Shipped 570 Fixes Tuesday. By Wednesday Its Serial Tormentor Dropped a Windows Zero-Day With No CVE and No Patch. LegacyHive Is Real, and Smaller Than the Headline.
Microsoft closed 570 vulnerabilities on July 14, its largest Patch Tuesday ever, with two zero-days already exploited in the wild. Hours later, a researcher who goes by Nightmare Eclipse — also seen as Chaotic Eclipse, and known around Redmond as a serial tormentor — published a working proof-of-concept for a Windows flaw that has no CVE, no advisory, and no security update. It is called LegacyHive, and it affects fully patched machines. Here is the honest read on what it is
Patrick Duggan
Jul 173 min read


Balbooa Forms Has an Unauthenticated File-Upload Bug CISA Says Is Being Exploited — and the Small Orgs Running It Have No One Watching
What Happened? There's a significant issue with Balbooa Forms, notably used by small clinics, nonprofits, local governments, and schools. CISA has listed CVE-2026-56291 — an Unrestricted Upload of File with Dangerous Type Vulnerability — as actively exploited. If you're part of a cash-strapped organization relying on Balbooa Forms, this is your wake-up call. Who's at Risk? This vulnerability affects those who use Balbooa Forms for data collection. These forms are often integr
Patrick Duggan
Jul 162 min read


In March We Named Medical Device Makers 'The Ones Getting Breached.' Then Medtronic, Stryker, Intuitive Surgical and UFP Proved It. We Caught Two and Missed Two — Here's the Honest Sector Map.
On March 15 we published a post with a thesis in the title: the medical device companies invisible to AI are the ones getting breached. Four months later that thesis has been proven four times over, and we owe you an honest accounting — because on two of those four we were early with receipts, and on the other two we went quiet at exactly the moment we should have been loudest. A threat-intel shop that only maps its wins is selling a brochure. This is the sector map with the
Patrick Duggan
Jul 164 min read


Your Claude Preferences Sync to Every Device. Pentera Turned That Into a Reverse Shell — and Anthropic Says It's Working as Designed.
This morning we wrote about a fake-click flaw in the Claude browser extension, and called it a clean teachable example of the failure mode that will define the next few years of agent security. Here is the companion piece from the desktop side, disclosed by Pentera Labs, and it makes the same argument from a different door. It also comes with a caveat we need to put up front, because the wire coverage has been calling it a one-click, zero-interaction attack, and that is not q
Patrick Duggan
Jul 164 min read


China Called Claude Code a Backdoor. The Uncomfortable Part Is That the Hidden Code Was Real — and We Run on Claude.
We run our entire threat intelligence operation on Claude. It writes our detections, drafts these posts, and reasons over our corpus. So when China's Ministry of Industry and Information Technology issued a formal warning this month that Anthropic's Claude Code contains a security backdoor, we are exactly the shop that has to look at it straight instead of reaching for the flag. Here is the honest read, and it does not land where either side wants it to. What China actually c
Patrick Duggan
Jul 164 min read


FamousSparrow Hit Azerbaijan's Oil and Gas Sector Through Exchange. The C2 Was in Our Feed Since May 14 — Two Months Before the Report Named It.
Bitdefender published a multi-wave intrusion this week against an Azerbaijani oil and gas company, running from late December 2025 through late February 2026. The credit for the analysis is theirs, and it is careful work — three waves, two backdoor families, and a nice piece of DLL-sideloading tradecraft we will walk through. We want to add one thing to it, because we can: the hard-coded command-and-control domain the primary backdoor calls home to was already sitting in our
Patrick Duggan
Jul 164 min read


We Checked the MCP Registry: Every Other Security Vendor's MCP Is a Doorway to a Product You Already Pay For. Ours Ships the Intelligence.
The Model Context Protocol registry is where AI clients — Claude Desktop, Cursor, and the rest — go to find and install servers that give an agent new abilities. We went through it looking at what the security industry has published, because we have a server there ourselves and we wanted an honest read on how it compares. The answer was cleaner than we expected, and it comes down to one distinction that has nothing to do with tool counts. Almost every security-vendor MCP in t
Patrick Duggan
Jul 164 min read


A Malicious Extension Can Trigger Claude's Browser Actions With a Fake Click — Because It Never Checks One Boolean. isTrusted Is the New Injection Surface.
Ax Sharma of Manifold Security found something in the Claude for Chrome extension that is worth understanding not because it is catastrophic — it is bounded, and we will be precise about how bounded — but because it is a clean, teachable example of a failure mode that is going to define the next few years of agent security. The extension fires its built-in actions when you click certain page elements, and it never checks whether the click came from a human being. A malicious
Patrick Duggan
Jul 165 min read


We Aimed Our New Hunter at the Fortune 500 and Found Fake Citrix, Cisco, and Fortinet Installers — Impersonating the VPN Clients Your IT Admins Use to Reach the Corporate Network.
Yesterday we built a hunter that finds fake-installer GitHub repositories by behavior, off the back of Arctic Wolf's report on a 292-repo campaign impersonating trusted software. Today we pointed it at a Fortune 500 brand list to answer a simple question: does the impersonation surface reach past crypto wallets and consumer apps into the enterprise? It does, and the cluster it surfaced is the one worth your attention. The consumer hits were the expected ones — fake QuickBooks
Patrick Duggan
Jul 164 min read


Arctic Wolf Named 292 Fake GitHub Repos Yesterday. We Built the Hunter Overnight and It Flagged Nine More on the First Run. Here's the Method — Steal It.
Yesterday Arctic Wolf published a campaign: 292 fake GitHub repositories impersonating trusted software, delivering an infostealer. Good research, and we credited it. But there are two ways to consume a report like that. You can read it, nod, and file it — which means the next 292 repos catch you exactly the same way. Or you can ask the more useful question: if a vendor found this class by hunting for it, why am I not hunting for it too? We asked that last night, built the hu
Patrick Duggan
Jul 164 min read
bottom of page