Sign in

Patrick Duggan

@hakksaww.bsky.social
450 followers 614 following 2.7K posts

Co-founder, DugganUSA LLC. Building Butterbot — threat intel + agentic AI. STIX feed serving 275+ orgs in 46 countries. Claude Code power user. Minneapolis. I do stupid data tricks. medium.com/@hacksawduggan

PostsRepliesMedia
Patrick Duggan @hakksaww.bsky.social · 16/08/2026
A reader asked for MISP. We shipped it in a day. Then the first manifest republished Spamhaus DROP under our org name. Laundering. Caught before anyone pulled it. www.dugganusa.com/post/a-reader-ask…
020
Patrick Duggan @hakksaww.bsky.social · 30/07/2026
We said five Minnesota water systems were attacked. It was more than thirty. Correcting our own number. The 21 indicators are still free, still no signup. www.dugganusa.com/post/we-said-five…
010
Patrick Duggan @hakksaww.bsky.social · 30/07/2026
You rotated the credentials. You re-imaged the laptop. The Russians still have the mailbox. The persistence is a folder permission, server-side in Exchange. www.dugganusa.com/post/you-rotated-…
000
Patrick Duggan @hakksaww.bsky.social · 30/07/2026
We published the ratio most threat-intel companies won't. 22% of our live feed is first-party — things our own sensors saw. The rest is public lists anyone can pull. Also live: 15 KEV entries had public exploit code BEFORE CISA listed them. analytics.dugganusa.com/first-party
000
Patrick Duggan @hakksaww.bsky.social · 30/07/2026
Cisco shipped a password inside the box that configures your firewalls. Deadline is Saturday. It scores 5.3, so your scanner won't rank it. Cisco overrode their own score. www.dugganusa.com/post/there-is-a-s…
000
Patrick Duggan @hakksaww.bsky.social · 29/07/2026
You patched that Fortinet box after the incident. Ticket closed. CISA just KEV'd a bypass of the eviction patch. It scores 5.3, so your scanner buries it below the noise. www.dugganusa.com/post/two-bugs-hit…
000
Patrick Duggan @hakksaww.bsky.social · 29/07/2026
Self-hosted Cal.com? A working exploit went public last night. One request, no auth, code execution. The bug isn't Cal.com's. It's the Next.js they bundled. www.dugganusa.com/post/a-cvss-10-0-…
000
Patrick Duggan @hakksaww.bsky.social · 28/07/2026
Five MN towns had water plant controls attacked this morning. 21 IPs from the federal PLC advisory are in our free blocklist. Grep your firewall logs back to March. www.dugganusa.com/post/five-minneso…
000
Patrick Duggan @hakksaww.bsky.social · 28/07/2026
crt.sh: one success in six calls. Most tools return "0 subdomains found" on failure. That reads as clean. Your last attack surface report may have found nothing. www.dugganusa.com/post/we-audited-o…
010
Patrick Duggan @hakksaww.bsky.social · 27/07/2026
He moved his botnet C2 to the blockchain so it couldn't be seized. Then wrote his confession into that same immutable record. You can't delete an ENS entry either. www.dugganusa.com/post/he-moved-his…
000
Patrick Duggan @hakksaww.bsky.social · 27/07/2026
Your MSP installed ScreenConnect to help you. Attackers now use it to get in. One click joins you to THEIR session. Signed, legit, nothing for EDR to block. Know your relay? www.dugganusa.com/post/operation-bl…
000
Patrick Duggan @hakksaww.bsky.social · 27/07/2026
Still running that forum from 2004? With 20 years of member emails and password hashes in it? Working pre-auth vBulletin exploit went public today. No login needed. www.dugganusa.com/post/a-public-exp…
001
Patrick Duggan @hakksaww.bsky.social · 27/07/2026
Who can create workflows in your n8n? That permission is shell on the host. Third sandbox escape in five months. No CVE — your scanner never told you. www.dugganusa.com/post/n8n-patched-…
000
Patrick Duggan @hakksaww.bsky.social · 15/07/2026
RedEye & Etairos cracked a 'ghost font' — words only human eyes can read, hidden in pure motion — in ~20 min with 1981 optical-flow math. Van Eck phreaking for the eyeball: www.dugganusa.com/post/a-ghost-font…
000
Patrick Duggan @hakksaww.bsky.social · 10/07/2026
War.gov's 4th UAP drop landed this morning — we ingested all 40 the same day. Full-text searchable + on the globe & timeline now. New: DOE nuclear files (Los Alamos '49, Pantex '15), Project Sign 1948, Navy "Range Fouler" forms. 335 docs → epstein.dugganusa.com/uap #UAP #UFO
100
Patrick Duggan @hakksaww.bsky.social · 09/07/2026
SimpleHelp CVE-2026-48558 is today's headline. We ran the full chain July 1: OIDC forgery → TaskWeaver → Djinn, the AI-key stealer. Primary catch: BlackPoint Cyber's APG. www.dugganusa.com/post/a-new-infost…
000
Patrick Duggan @hakksaww.bsky.social · 05/07/2026
Peter Thiel told an unrecorded Aspen panel that Anthropic will “rig the elections in 2028.” CNN: “an unsupported conspiratorial claim.” So we inventoried the election-shaping machinery that verifiably exists. It runs through his network. www.dugganusa.com/post/thiel-rig-20…
100
Patrick Duggan @hakksaww.bsky.social · 03/07/2026
Karp says enterprises pay for tokens that create no value. Ours found and fixed 4 production failures today — receipts, timestamps, and the disclosure he skipped: www.dugganusa.com/post/alex-karp-sa… #AI
010
Patrick Duggan @hakksaww.bsky.social · 30/06/2026
The breach that hurts you won't be yours — it's your vendor's. Today: Texas Parks & Wildlife, 3M+ people's license & passport data leaked via a license vendor. "Not compromised." Again. www.dugganusa.com/post/nissan-s-fou…
000
Patrick Duggan @hakksaww.bsky.social · 29/06/2026
🔴 Splunk Enterprise CVE-2026-20253: unauth file write via the PostgreSQL sidecar → RCE. watchTowr PoC is public; now on CISA KEV. On-prem Splunk = patch today. #threatintel www.securityweek.com/splunk-enterpr…
000
Patrick Duggan @hakksaww.bsky.social · 23/06/2026
--text Scattered Spider + LAPSUS$ + ShinyHunters as one federated brand: Scattered LAPSUS$ Hunters. Extortion-as-a-franchise. Affiliates pay for access to infra. Custom ransomware in dev: Sh1nySp1d3r. We called it the Coinbase Cartel in May. Resecurity confirmed it.
000
Patrick Duggan @hakksaww.bsky.social · 16/06/2026
Confirmed today: Miasma is poisoning MCP packages + CLAUDE.md across 14/59 campaigns. Our PyPI feed went live this morning already holding 24 malicious MCP packages. www.dugganusa.com/post/we-turned-on…
000
Patrick Duggan @hakksaww.bsky.social · 14/06/2026
Raw count says AWS is the worst host on earth. Divide by IP footprint and the real answer is BUCKLOG — a 6-month-old Paris /24, ~420,000x denser than AWS. #ThreatIntel www.dugganusa.com/post/volume-says-…
010
Patrick Duggan @hakksaww.bsky.social · 14/06/2026
Handala 'hacked Cal Water' — but the dump is billing + a GPS server. No OT, no SCADA. The water was never in play. 'We could've done worse' is the payload. #ThreatIntel www.dugganusa.com/post/handala-hit-…
000
Patrick Duggan @hakksaww.bsky.social · 14/06/2026
DefiLlama: Q2 was crypto's worst quarter ever — ~70 hacks, $746M. The 2 biggest (Drift, Kelp — both Lazarus) didn't break code. They broke trust. #ThreatIntel www.dugganusa.com/post/defillama-sa…
000
Patrick Duggan @hakksaww.bsky.social · 13/06/2026
Law enforcement seized AudiA6 this week — the crypto-laundering rail that washed $389M for at least 15 ransomware crews. Including the ones who stole your Carnival records and hit 320+ orgs as TheGentlemen. The takedown is real. The demand for laundering isn't going anywhere.
100
Patrick Duggan @hakksaww.bsky.social · 13/06/2026
Microsoft patched YellowKey, the BitLocker bypass it credited to the researcher it banned from GitHub. Within days he dropped a SECOND one — GreatXML — on his own server, where Microsoft can't take it down. And the trigger is running a Microsoft Defender scan.
100
Patrick Duggan @hakksaww.bsky.social · 12/06/2026
400,750 DOJ Epstein documents, searchable in one box. No login, no paywall, no FOIA officer to wait on. Type a name, get the pages — we OCR'd the whole release and put it behind a search bar. The gift that keeps on giving 🎁 epstein.dugganusa.com
000
Patrick Duggan @hakksaww.bsky.social · 11/06/2026
ShinyHunters built their name on phone calls to the help desk: social-engineer an MFA reset, walk into Salesforce, export the CSV. This week they changed weapons — a 9.8 unauth RCE zero-day in Oracle PeopleSoft, CVE-2026-35273. 100+ orgs breached. The capability shift is the story.
100
Patrick Duggan @hakksaww.bsky.social · 11/06/2026
Three exploit PoCs hit GitHub this week. We'd already published on all three before the code dropped. Our harvester caught the PoCs landing; our blog made the calls. This is what left-of-PoC looks like. Receipts below.
100
Patrick Duggan @hakksaww.bsky.social · 06/06/2026
Hospital fell to LockBit this weekend. CISA flagged Cisco SD-WAN Manager (vManage) auth-bypass CVEs, exploited — admin on every router. Exposed vManage? Kill it tonight: www.dugganusa.com/post/a-hospital-f…
020
Patrick Duggan @hakksaww.bsky.social · 04/06/2026
Caught the cPanel exploit (CVE-2026-41940) May 11. CISA listed it June 4. Public exploit = attack cost ~$0; you still pay weeks to patch. That 24-day gap is the breach: www.dugganusa.com/post/we-flagged-t…
080
Patrick Duggan @hakksaww.bsky.social · 04/06/2026
Mass-exploited right now: Citrix NetScaler CVE-2026-3055 — a 9.8 SAML memory overread. Patch, then ROTATE the SAML signing cert (overread = assume leaked): www.dugganusa.com/post/citrix-netsc…
110
Patrick Duggan @hakksaww.bsky.social · 03/06/2026
Verizon DBIR 2026: exploitation beat credential theft (31% vs 13%). Our harvest: 3 days from CVE to active campaign. 43-day median patch time. That gap is the whole problem. www.dugganusa.com/post/verizon-s-db…
000
Patrick Duggan @hakksaww.bsky.social · 03/06/2026
Gamaredon hides GammaWorm in NTFS Alternate Data Streams. Your AV won't find it. 20K lines obfuscated VBScript. Telegram DDR C2. wscript.exe with a colon in the path is the detection. www.dugganusa.com/post/gamaredon-s-…
000
Patrick Duggan @hakksaww.bsky.social · 03/06/2026
Miasma: 95 Red Hat npm packages backdoored. Mini Shai-Hulud rebranded — same TeamPCP worm, new GCP+Azure identity collectors. One GitHub account. Commit hashes in our feed. www.dugganusa.com/post/miasma-backd…
000
Patrick Duggan @hakksaww.bsky.social · 03/06/2026
SilentPush named DriveSurge yesterday — the IAB behind thousands of ClickFix infections. We had their infrastructure indexed since February. The receipt is timestamped. www.dugganusa.com/post/silentpush-n…
000
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
Claude Opus was named coordinator in an AI-built ransomware framework. We use Claude Opus. Same model, different hands. The discipline is the differentiator. www.dugganusa.com/post/claude-opus-…
000
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
We asked what our engine rated max confidence across 8.36M decisions. China Telecom. Trying our door. Three times. Caught each time. Now in 50 OTX pulses. www.dugganusa.com/post/we-looked-at…
020
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
1.5B Salesforce records. 760 orgs. 12 security vendors in the victim list. TruffleHog. OAuth tokens in Salesloft's source code. We were writing about this in Sep 2025. www.dugganusa.com/post/the-saleslof…
030
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
The Vercel breach wasn't a hack. Lumma → Context.ai → OAuth → Vercel employee. MFA never triggered. Full chain, IOCs, and the domain we flagged 7 months early. www.dugganusa.com/post/the-vercel-b…
030
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
We caught the SharePoint exploit before Microsoft warned about it. We still can't get a meeting with Glasswing. The receipts are public. Come check the timestamps. www.dugganusa.com/post/we-caught-th…
000
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
SharePoint CVE-2026-32201 actively targeted. The paths: /_layouts/15/notify.aspx + /start.aspx. Unauthenticated spoofing. Patch Tuesday June 9 — interim detection is now. www.dugganusa.com/post/sharepoint-c…
000
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
Cisco's acquiring the AI-security stack — Astrix, Galileo, AI Defense. The one layer you can't buy at $9B scale: early, cheap, left-of-boom threat intel. We run it for $384/mo. www.dugganusa.com/post/cisco-s-ai-m…
000
Patrick Duggan @hakksaww.bsky.social · 02/06/2026
CVE-2026-8732 (WP Maps Pro, 9.8) is being exploited TODAY to mint rogue WP admins. We harvested the PoCs May 30 — endpoints + the 'role' header + creds — 3 days early. $384/mo. www.dugganusa.com/post/the-wordpres…
000
Patrick Duggan @hakksaww.bsky.social · 01/06/2026
MuddyWater (Iran/MOIS) ran an espionage op disguised as 'Chaos' ransomware. Rapid7 unmasked it — their exfil server + rotation domains sat in our feed since March. 🧵 www.dugganusa.com/post/iran-dressed…
120
Patrick Duggan @hakksaww.bsky.social · 28/05/2026
CISA Exchange CVE-2026-42897 federal deadline tomorrow. Three more crews hit this week: Marquis (400K), Brightspeed via Crimson Collective (1M+), Silent Ransom Group on law firms. All four in our STIX feed: analytics.dugganusa.com/stix/regist…
060
Patrick Duggan @hakksaww.bsky.social · 22/05/2026
Verizon DBIR 2026: vulnerability exploitation is now the top breach vector. We shipped Pattern 53 for that shape 48 hours ago. They observe history. We instrument now. www.dugganusa.com/post/verizon-dbir…
090
Patrick Duggan @hakksaww.bsky.social · 21/05/2026
The cyber industry calls 1 thing "the edge." 10,000 edges per minute now. Dev laptop. IDE plugin. CI token. MCP server. OAuth scope. Wall is failing. Decision boundary is the perimeter. www.dugganusa.com/post/edges-are-al…
050
Patrick Duggan @hakksaww.bsky.social · 21/05/2026
One npm package this week. GitHub. OpenAI. Mistral. Grafana. All breached through it. CISA admin tokens sat public on GitHub 6 months. Defenders ARE the supply chain. www.dugganusa.com/post/the-week-the…
020