We said five Minnesota water systems were attacked. It was more than thirty. Correcting our own number. The 21 indicators are still free, still no signup. https://www.dugganusa.com/post/we-said-five-minnesota-water-systems-it-was-more-than-thirty-the-21-indicators-are-still-free
Patrick Duggan
@hakksaww.bsky.social
Co-founder, DugganUSA LLC. Building Butterbot — threat intel + agentic AI. STIX feed serving 275+ orgs in 46 countries. Claude Code power user. Minneapolis. I do stupid data tricks. https://medium.com/@hacksawduggan
You rotated the credentials. You re-imaged the laptop. The Russians still have the mailbox. The persistence is a folder permission, server-side in Exchange. https://www.dugganusa.com/post/you-rotated-the-credentials-and-re-imaged-the-laptop-the-russians-still-have-the-mailbox
We published the ratio most threat-intel companies won't. 22% of our live feed is first-party — things our own sensors saw. The rest is public lists anyone can pull. Also live: 15 KEV entries had public exploit code BEFORE CISA listed them. https://analytics.dugganusa.com/first-party
Cisco shipped a password inside the box that configures your firewalls. Deadline is Saturday. It scores 5.3, so your scanner won't rank it. Cisco overrode their own score. https://www.dugganusa.com/post/there-is-a-static-password-in-the-box-that-manages-your-cisco-firewalls-you-have-until-saturday
You patched that Fortinet box after the incident. Ticket closed. CISA just KEV'd a bypass of the eviction patch. It scores 5.3, so your scanner buries it below the noise. https://www.dugganusa.com/post/two-bugs-hit-kev-the-same-day-the-10-0-gets-them-in-the-5-3-keeps-them-there
Self-hosted Cal.com? A working exploit went public last night. One request, no auth, code execution. The bug isn't Cal.com's. It's the Next.js they bundled. https://www.dugganusa.com/post/a-cvss-10-0-exploit-for-cal-com-landed-on-github-last-night-the-bug-is-not-cal-com-s-it-is-the-ne
Five MN towns had water plant controls attacked this morning. 21 IPs from the federal PLC advisory are in our free blocklist. Grep your firewall logs back to March. https://www.dugganusa.com/post/five-minnesota-towns-had-their-water-controls-attacked-this-morning-here-are-21-ip-addresses-to-gre
crt.sh: one success in six calls. Most tools return "0 subdomains found" on failure. That reads as clean. Your last attack surface report may have found nothing. https://www.dugganusa.com/post/we-audited-our-own-instruments-for-one-day-ten-were-lying-four-of-the-lies-were-green-checkmarks
He moved his botnet C2 to the blockchain so it couldn't be seized. Then wrote his confession into that same immutable record. You can't delete an ENS entry either. https://www.dugganusa.com/post/he-moved-his-botnet-to-the-blockchain-so-nobody-could-take-it-down-then-he-wrote-his-own-confession
Your MSP installed ScreenConnect to help you. Attackers now use it to get in. One click joins you to THEIR session. Signed, legit, nothing for EDR to block. Know your relay? https://www.dugganusa.com/post/operation-bluedash-ships-no-malware-it-ships-screenconnect-and-your-edr-is-fine-with-that
Still running that forum from 2004? With 20 years of member emails and password hashes in it? Working pre-auth vBulletin exploit went public today. No login needed. https://www.dugganusa.com/post/a-public-exploit-just-landed-for-vbulletin-the-first-fix-for-this-class-shipped-with-no-cve-at-all
Who can create workflows in your n8n? That permission is shell on the host. Third sandbox escape in five months. No CVE — your scanner never told you. https://www.dugganusa.com/post/n8n-patched-this-sandbox-in-february-somebody-walked-around-the-patch-there-is-no-cve
RedEye & Etairos cracked a 'ghost font' — words only human eyes can read, hidden in pure motion — in ~20 min with 1981 optical-flow math. Van Eck phreaking for the eyeball: https://www.dugganusa.com/post/a-ghost-font-claimed-only-human-eyes-could-read-it-redeye-beat-it-in-20-minutes-with-1981-math-t
War.gov's 4th UAP drop landed this morning — we ingested all 40 the same day. Full-text searchable + on the globe & timeline now. New: DOE nuclear files (Los Alamos '49, Pantex '15), Project Sign 1948, Navy "Range Fouler" forms. 335 docs → https://epstein.dugganusa.com/uap #UAP #UFO
SimpleHelp CVE-2026-48558 is today's headline. We ran the full chain July 1: OIDC forgery → TaskWeaver → Djinn, the AI-key stealer. Primary catch: BlackPoint Cyber's APG. https://www.dugganusa.com/post/a-new-infostealer-is-hunting-your-claude-gemini-and-codex-keys-it-gets-in-through-your-help-desk
Peter Thiel told an unrecorded Aspen panel that Anthropic will “rig the elections in 2028.” CNN: “an unsupported conspiratorial claim.” So we inventoried the election-shaping machinery that verifiably exists. It runs through his network. https://www.dugganusa.com/post/thiel-rig-2028-receipts
Karp says enterprises pay for tokens that create no value. Ours found and fixed 4 production failures today — receipts, timestamps, and the disclosure he skipped: https://www.dugganusa.com/post/alex-karp-says-enterprises-pay-for-tokens-that-create-no-value-our-tokens-fixed-four-production-fai #AI
The breach that hurts you won't be yours — it's your vendor's. Today: Texas Parks & Wildlife, 3M+ people's license & passport data leaked via a license vendor. "Not compromised." Again. https://www.dugganusa.com/post/nissan-s-fourth-breach-in-four-years-wasn-t-nissan-s-that-s-the-whole-problem
🔴 Splunk Enterprise CVE-2026-20253: unauth file write via the PostgreSQL sidecar → RCE. watchTowr PoC is public; now on CISA KEV. On-prem Splunk = patch today. #threatintel https://www.securityweek.com/splunk-enterprise-vulnerability-exploited-in-attacks-days-after-disclosure/
--text Scattered Spider + LAPSUS$ + ShinyHunters as one federated brand: Scattered LAPSUS$ Hunters. Extortion-as-a-franchise. Affiliates pay for access to infra. Custom ransomware in dev: Sh1nySp1d3r. We called it the Coinbase Cartel in May. Resecurity confirmed it.
Confirmed today: Miasma is poisoning MCP packages + CLAUDE.md across 14/59 campaigns. Our PyPI feed went live this morning already holding 24 malicious MCP packages. https://www.dugganusa.com/post/we-turned-on-a-pypi-feed-this-morning-it-found-24-malicious-mcp-packages-one-named-runcommand-se
Raw count says AWS is the worst host on earth. Divide by IP footprint and the real answer is BUCKLOG — a 6-month-old Paris /24, ~420,000x denser than AWS. #ThreatIntel https://www.dugganusa.com/post/volume-says-aws-is-the-worst-host-alive-abuse-per-ip-says-it-s-a-6-month-old-paris--24-called-buckl
Handala 'hacked Cal Water' — but the dump is billing + a GPS server. No OT, no SCADA. The water was never in play. 'We could've done worse' is the payload. #ThreatIntel https://www.dugganusa.com/post/handala-hit-cal-water-s-billing-database-and-a-gps-server-not-the-water-supply-the-restraint-is-t
DefiLlama: Q2 was crypto's worst quarter ever — ~70 hacks, $746M. The 2 biggest (Drift, Kelp — both Lazarus) didn't break code. They broke trust. #ThreatIntel https://www.dugganusa.com/post/defillama-says-q2-was-crypto-s-worst-quarter-ever-70-hacks-746m-the-two-biggest-drained-trust-n
Law enforcement seized AudiA6 this week — the crypto-laundering rail that washed $389M for at least 15 ransomware crews. Including the ones who stole your Carnival records and hit 320+ orgs as TheGentlemen. The takedown is real. The demand for laundering isn't going anywhere.
Microsoft patched YellowKey, the BitLocker bypass it credited to the researcher it banned from GitHub. Within days he dropped a SECOND one — GreatXML — on his own server, where Microsoft can't take it down. And the trigger is running a Microsoft Defender scan.
400,750 DOJ Epstein documents, searchable in one box. No login, no paywall, no FOIA officer to wait on. Type a name, get the pages — we OCR'd the whole release and put it behind a search bar. The gift that keeps on giving 🎁 https://epstein.dugganusa.com
ShinyHunters built their name on phone calls to the help desk: social-engineer an MFA reset, walk into Salesforce, export the CSV. This week they changed weapons — a 9.8 unauth RCE zero-day in Oracle PeopleSoft, CVE-2026-35273. 100+ orgs breached. The capability shift is the story.
Three exploit PoCs hit GitHub this week. We'd already published on all three before the code dropped. Our harvester caught the PoCs landing; our blog made the calls. This is what left-of-PoC looks like. Receipts below.
Hospital fell to LockBit this weekend. CISA flagged Cisco SD-WAN Manager (vManage) auth-bypass CVEs, exploited — admin on every router. Exposed vManage? Kill it tonight: https://www.dugganusa.com/post/a-hospital-fell-to-lockbit-this-weekend-while-cisa-cataloged-cisco-s-sd-wan-brain-as-a-weapon-same