Patrick Duggan

@hakksaww.bsky.social

Co-founder, DugganUSA LLC. Building Butterbot — threat intel + agentic AI. STIX feed serving 275+ orgs in 46 countries. Claude Code power user. Minneapolis. I do stupid data tricks. https://medium.com/@hacksawduggan

--text Scattered Spider + LAPSUS$ + ShinyHunters as one federated brand: Scattered LAPSUS$ Hunters. Extortion-as-a-franchise. Affiliates pay for access to infra. Custom ransomware in dev: Sh1nySp1d3r. We called it the Coinbase Cartel in May. Resecurity confirmed it.

Law enforcement seized AudiA6 this week — the crypto-laundering rail that washed $389M for at least 15 ransomware crews. Including the ones who stole your Carnival records and hit 320+ orgs as TheGentlemen. The takedown is real. The demand for laundering isn't going anywhere.

Microsoft patched YellowKey, the BitLocker bypass it credited to the researcher it banned from GitHub. Within days he dropped a SECOND one — GreatXML — on his own server, where Microsoft can't take it down. And the trigger is running a Microsoft Defender scan.

ShinyHunters built their name on phone calls to the help desk: social-engineer an MFA reset, walk into Salesforce, export the CSV. This week they changed weapons — a 9.8 unauth RCE zero-day in Oracle PeopleSoft, CVE-2026-35273. 100+ orgs breached. The capability shift is the story.

Three exploit PoCs hit GitHub this week. We'd already published on all three before the code dropped. Our harvester caught the PoCs landing; our blog made the calls. This is what left-of-PoC looks like. Receipts below.