Sign in

Taggart

@taggart-tech.com
4.8K followers 964 following 5.1K posts

@mttaggart@infosec.exchange. Displaced Philly boy. Executive Director of @ifin-intel.org. Threat hunter. Educator. Dad. General in the AI Resistance. taggartinstitute.org wtfbins.wtf linktr.ee/mttaggart

PostsRepliesMedia
Taggart @taggart-tech.com · 16h
I stg 10 minutes with pen on paper gets more and better thinking out of me than a whole damn day in front of a keyboard getting yanked this way and that by the notification blitz we've created for ourselves.
060
Reposted by Taggart
IFIN @ifin-intel.org · 29/09/2026
If you're involved in vulnerability management/VulnOps, the last several months have been overwhelming. But take heart: there is a path forward, despite the madness surrounding us.
ifin-intel.org
Finding the Signal in the Vulnerability Noise | IFIN
The flood of new CVEs can make it hard to know what matters. But there are tools to help find our way.
086
Reposted by Taggart
IFIN @ifin-intel.org · 29/09/2026
We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed. ifin.network/t/multi... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Multiple Citrix Netscaler 0-Days Exploited
Last Updated: 2026-09-29T14:53:55Z (UTC) What’s Happening Citrix has disclosed 8 critical CVEs. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 There’s also an associated blog post. Affected Versions Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23 Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279 Indicato...
275
Taggart @taggart-tech.com · 29/09/2026
This NVidia OpenShell thing is wild insofar as I've never seen a GitHub repo get so much press. That's what the "Open Agent Safety Platform" is. Well that and some proprietary gear that it's "optimized" for.
000
Taggart @taggart-tech.com · 28/09/2026
I watched this movie recently and had to just sit and think about how good it was for a while. Especially as an American, there are parts of the post-WWII story in Japan that you're not easily exposed to, and that really mattered.
010
Taggart @taggart-tech.com · 28/09/2026
My electric bill far outstrips my car payment.
230
Reposted by Taggart
Taggart @taggart-tech.com · 28/09/2026
Someone on here is accusing me of breaching confidentiality and lying about it, without evidence. I was provided with reliable Intel without restrictions, but from a source that didn't want to be named. That is consistent with TLP and CTI/journalism standards.
121
Taggart @taggart-tech.com · 28/09/2026
Since I apparently have to make this clear: I'm not advocating for breaching TLP; I'm advocating defaulting to disclosure. Also, confidential sourcing and TLP are compatible, and even mentioned in the TLP docs. Confidential sourcing is not the same as "breaching" TLP.
170
Reposted by Taggart
Taggart @taggart-tech.com · 27/09/2026
Today is very effectively making the argument for us at IFIN that TLP:CLEAR should be the *default*, and only extremely sensitive intelligence should be withheld. Active exploitation is not a reason to withhold, given the fact that more information always advantages defenders.
0114
Reposted by Taggart
Nicholas Grossman @nicholasgrossman.bsky.social · 27/09/2026
What's a good way to visualize how the AI boom/bubble is propping up the economy? Ah, thanks.
12706189
Taggart @taggart-tech.com · 27/09/2026
Today is very effectively making the argument for us at IFIN that TLP:CLEAR should be the *default*, and only extremely sensitive intelligence should be withheld. Active exploitation is not a reason to withhold, given the fact that more information always advantages defenders.
0114
Reposted by Taggart
IFIN @ifin-intel.org · 27/09/2026
Patches are available and updated versions are now listed.
073
Taggart @taggart-tech.com · 27/09/2026
Updated with the latest from Citrix.
030
Taggart @taggart-tech.com · 27/09/2026
Literally as I'm typing this Citrix releases their advisory: support.citrix.com/support-home...
support.citrix.com
Loading...
040
Taggart @taggart-tech.com · 27/09/2026
I have seen this "writeup" of the new Citrix 0-days but there's no correlation with anything, no sourcing (Citrix has not released a patch to diff), so I'm very skeptical.
sh3llc0d3.com
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...
220
Reposted by Taggart
Joe Uchill @joeuchill.bsky.social · 27/09/2026
Finally, we can burn sources and methods at speed.
0157
Reposted by Taggart
Sweetbabette @sweetbabette.bsky.social · 27/09/2026
The Phillies organization should go to a late night cheesesteak place and interview the first 5 people in line wearing Phillies gear and put the most specifically hurtful one in the locker room pre-game tomorrow
712524
Taggart @taggart-tech.com · 27/09/2026
Finally got enough on this to publish. Developing story.
070
Reposted by Taggart
Sarah McAnulty, Ph.D. @sarahmackattack.bsky.social · 25/09/2026
If you care about keeping the Academy of Natural Sciences open to the public in Philadelphia, I need you to read and share this thread. Trish Wellenbach was sent from the mayor's office to oversee the Academy of Natural sciences situation. She needs to hear from us. Here comes the action item:
14549482
Reposted by Taggart
Gwen C. Katz @gwenckatz.bsky.social · 25/09/2026
Fuck ChatGPT flyers. The future is broadsheets.
A crowded broadsheet with way too many fonts. It says:
Forget ChatGPT Flyers
Say it with 
Broadsheets
Unlimited fonts
Stretch them
Or cram a really long sentence into one line for no good reason
No whitespace
Mix capital and lowercase
Pointing hands
(They're called manicules!)
Don't be left behind
Broadsheets are the future
203186145247
Taggart @taggart-tech.com · 25/09/2026
Do you know them?
mttagg.art
Learn the Stars
010
Reposted by Taggart
Clara Jeffery @clarajeffery.bsky.social · 24/09/2026
We just dropped a bombshell investigation into ChatGPT's role in the Tumbler Ridge mass shooting. Incredible reporting from @markfollman.bsky.social that will have far-reaching effects...hopefully: www.motherjones.com/media/2026/0...
motherjones.com
ChatGPT helped the Tumbler Ridge school shooter focus on guns, tactics, and terror, our investigation reveals
OpenAI’s chatbot fed the shooter’s violent fantasies and planning up to the massacre.
271467745
Reposted by Taggart
Preeti Chhibber @runwithskizzers.bsky.social · 24/09/2026
all these people sound like this:
62261531
Taggart @taggart-tech.com · 24/09/2026
Whenever an AI company tells you about security, believe the opposite.
mouse.dev
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB | Mouse
I asked Muse to archive the files it could see and send them to my Google Drive. It did.
14822
Reposted by Taggart
Rowdy @r0wdy.sk33t.expert · 24/09/2026
A neat twist to CTF competitions could be something like capturing the flag(or flags) isn’t how you win it’s teaching someone else how to capture it
5113
Reposted by Taggart
Taggart @taggart-tech.com · 23/09/2026
You know, if tech companies are looking for a, uh, less *problematic* non-profit to fund, I have some thoughts...
ifin-intel.org
IFIN | The Independent Federated Intelligence Network
A not-for-profit organization dedicated to the teaching of best practices in cyber threat intelligence, and the mutual sharing of timely, actionable, and relevant intelligence among the community.
0104
Reposted by Taggart
JiSe @jise.bsky.social · 23/09/2026
Another thing that worries me about these is that as we have seen, there is really no easy way to make sure something you sack an AI to do, will be done within scope and safely. Preparing people to just go "Hey Claude, hack this box" will inevitably lead into some horrible scenarios when done IRL.
111
Reposted by Taggart
Taggart @taggart-tech.com · 23/09/2026
Making this about throwing tokens at a flag mistakes the flag for the value of a CTF, rather than the path that leads to the flag.
151
Reposted by Taggart
Taggart @taggart-tech.com · 23/09/2026
Sorry, still annoyed about this, especially from someone I used to really look up to. The entire point of a CTF is to build skill—the very skill, by the way, necessary to verify any model output in a given field. Without knowing the stuff yourself, you can never know whether the model got it right.
182
Reposted by Taggart
IFIN @ifin-intel.org · 23/09/2026
The best time to block the finger protocol (port 79/tcp) outbound from your network was like…the second Clinton administration? But now's a good time too. #ThreatIntel #ThreatIntelligence #IFIN
2104
Taggart @taggart-tech.com · 23/09/2026
Sorry, but I think I'll pass. I don't need to know how good the models are at CTFs; we just had a bunch of news stories about that.
John Hammond announcing the Huntress CTF in which use of AI is strongly encouraged.
5123
Taggart @taggart-tech.com · 23/09/2026
OpenWRT is among the OSes impacted by this.
082
Taggart @taggart-tech.com · 23/09/2026
You know, if tech companies are looking for a, uh, less *problematic* non-profit to fund, I have some thoughts...
ifin-intel.org
IFIN | The Independent Federated Intelligence Network
A not-for-profit organization dedicated to the teaching of best practices in cyber threat intelligence, and the mutual sharing of timely, actionable, and relevant intelligence among the community.
0104
Reposted by Taggart
IFIN @ifin-intel.org · 23/09/2026
A format string vulnerability in Shrubbery's TACACS+ library (and Facebook's archived fork of it) can lead to secret disclosure, DoS, and potentially remote code execution. No, Cisco gear isn't affected, but many other devices will be. As of now, no CVE has been assigned.
ifin.network
CVE pending: pre-auth format-string bug in tac_plus (Shrubbery Networks)
Last Updated: 2026-09-23T15:47:14Z (UTC) CVE: TBA CVSSv3: tentative 9.8 (per vuln publisher, not ratified) What’s Happening Research firm elttam has disclosed a vulnerability in the Shrubbery fork of the tac_plus TACACS+ authentication library used in multiple networking devices. The vulnerability, if fully exploited, can lead to remote code execution on target devices. Crashing systems is also a possibility. Secret disclosure is a natural result of this vulnerability. The post is long,...
032
Reposted by Taggart
IFIN @ifin-intel.org · 22/09/2026
Completing our tour of new known-exploited vulns today, here is Arista's perfect-10. ifin.network/t/arist... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Arista CVE-2026-93952 Auth Bypass Exploited in the Wild
Last Updated: 2026-09-22T22:18:11Z (UTC) Arista published a security advisory today regarding its VeloCloud Orchestrator. The perfect-10 CVSS vulnerability: …may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Yes, it “may” indeed. It’s now confirmed exploited and on CISA’s KEVs as of today. Ther...
031
Taggart @taggart-tech.com · 22/09/2026
It's been kinda slow, and then today's just been bananas.
020
Reposted by Taggart
IFIN @ifin-intel.org · 22/09/2026
When it rains, it pours. F5 BIG-IP APM also has an exploited CVE! ifin.network/t/f5-bi... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
F5 BIG-IP CVE-2026-94127 RCE Exploited
Last Updated: 2026-09-22T20:36:25Z (UTC) What’s Happening A F5 advisory published 2026-09-22 details CVE-2026-94127 (CVSSv3 9.8). When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). It is unknown how common this configuration is as of this writing. Affected Products/Versions The affected product is BIG-IP APM (Access Policy Manager), versions: 21.1.0, patched in Hotfix-BIGIP-21.1.0...
052
Reposted by Taggart
IFIN @ifin-intel.org · 22/09/2026
Two Check Point critical vulnerabilities are now listed as exploited in the wild. ifin.network/t/cve-2... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
CVE-2026-85102 and 93616 - Check Point Security Gateway RCE/Path Traversal Exploited
Last updated: 2026-09-22T19:41:29Z (UTC) CVSSv3: 9.8 What’s Happening In what’s-old-is-new-again news, two CVEs were released today for Checkpoint Security Gateway management toolsets, including a pre-auth remote code execution and a path traversal in the management web service. Here are Check Points internal support center details: Since I started writing this Check Point posted notification of exploitation on their blog. Actions Check the advisories above for affected versions and o...
033
Reposted by Taggart
Taggart @taggart-tech.com · 22/09/2026
Keep scrolling
mttagg.art
Monitoring the Situation
121
Taggart @taggart-tech.com · 22/09/2026
Keep scrolling
mttagg.art
Monitoring the Situation
121
Taggart @taggart-tech.com · 21/09/2026
Feeling really good about use of work time today.
A movie cover for "Hot Girl Summer," but the three girls' faces have been overlaid with OpenAI, Anthropic, and Gemini logos. The "Girl" has been scratched out and replaced with COMPUTER CRIME
030
Taggart @taggart-tech.com · 21/09/2026
I'm too tired for even the "What can possibly go wrong?" of it all. Every day they build new ways to take your agency from you. Every day they add to the house of cards that can only end one way.
blog.cloudflare.com
Python Workers are now generally available
Python Workers allow developers to run Python web frameworks and AI orchestration libraries natively in the Cloudflare Workers runtime. You can seamlessly integrate with Cloudflare's ecosystem including D1, R2, and Workers AI without writing any JavaScript glue code.
111
Reposted by Taggart
Ted McCormick @tedmccormick.bsky.social · 19/09/2026
if you don't think humanistic learning has value in its own right, no amount of instrumentalization is going to save it that epochal decline coincided with the hegemony of the "employable skills" pitch, including earnings data and all the trimmings, ought to have taught us that
425657
Taggart @taggart-tech.com · 20/09/2026
A computer can never be held accountable Therefore A computer is the perfect patsy
0102
Taggart @taggart-tech.com · 18/09/2026
There's a part of the 3 Body Problem series where technology shifts to all metal because of a lack of plastics and like, yes give me the stainless steel streamline moderne future we were promised in the 30s
041
Reposted by Taggart
IFIN @ifin-intel.org · 18/09/2026
Rust maintainers are targeted (again), but good news: the same defenses as always apply. ifin.network/t/rust-... #ThreatIntel #ThreatIntelligence #IFIN #Rustlang
ifin.network
Rust Package Maintainers Targeted with Social Engineering, Repo Takeover
Last Updated: 2026-09-18T12:35:00Z (UTC) What’s Happening According to the Rust language security response working group, maintainers of rust-lang (the repo comprising the Rust language itself) and popular packages (crates) are being targeted by social engineering attacks intended to compromise the repository. Per the post: A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that’s used as a vector to either g...
031
Taggart @taggart-tech.com · 18/09/2026
Incredibly goofy work here. Patched now, but you could pwn Claude and Codex thanks to confusion between commit hashes and branch names. Microsoft hasn't patched.
air.security
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent.
091
Taggart @taggart-tech.com · 17/09/2026
The unsealed motion for summary judgment in the NYT/OpenAI/Microsoft case is a banger. arstechnica.com/tech... Full document: cdn.arstechnica.net/...
arstechnica.com
Microsoft exec called AI scraping the “largest theft of labor in human history”
Microsoft, OpenAI emails reveal fear of AI “doom loop” killing news orgs.
162
Taggart @taggart-tech.com · 17/09/2026
Operators are standing by to take your post!
010
Reposted by Taggart
IFIN @ifin-intel.org · 17/09/2026
Got a #cybersecurity question? Don't ask AI. Ask people who know. Join us at ifin.network.
ifin.network
IFIN
The Independent Federated Intelligence Network
032