Sign in

Taggart

@taggart-tech.com
4.8K followers 964 following 5.1K posts

@mttaggart@infosec.exchange. Displaced Philly boy. Executive Director of @ifin-intel.org. Threat hunter. Educator. Dad. General in the AI Resistance. taggartinstitute.org wtfbins.wtf linktr.ee/mttaggart

PostsRepliesMedia
Reposted by Taggart
Zack Whittaker @zackwhittaker.com · 3h
The Pentagon is notifying millions of current and former U.S. military servicemembers and staff that hackers stole their *unencrypted* personal information during a months-long data breach. The agency that had the breach also handles ID and login/credential access to U.S. military systems and bases.
techcrunch.com
Hackers stole millions of US military personnel records during months-long data breach | TechCrunch
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long breach.
1691104658
Reposted by Taggart
IFIN @ifin-intel.org · 4h
Well would you look at that; it's Cisco 0-day o'clock again. ifin.network/t/cve-2... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
CVE-2026-76504: Cisco SD-WAN Auth Bypass Actively Exploited
Last Updated: 2026-09-30T18:22:15Z (UTC) What’s Happening Cisco has released an advisory for CVE-2026-76504, a CVSSv3 9.8 Authentication Bypass in Cisco Catalyst SD-WAN Manager. All products running SD-WAN Manager are affected. Cisco has reported that the vulnerability has been exploited in the wild. Affected Versions Cisco Catalyst SD-WAN Software Release First Fixed Release Earlier than 20.9 Migrate to a fixed release. 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.1...
041
Taggart @taggart-tech.com · 6h
My experience teaching (including in boys' schools) tells me how important role models are. "I wanna be like *him*" is a driving force.
080
Taggart @taggart-tech.com · 6h
I wish I had a better answer, but in my view the best place to win this battle is in elementary and middle school. Boys need to see different kinds of role models than what our culture has provided.
180
Taggart @taggart-tech.com · 7h
There's some other version of masculinity that needs to ascend, and put that particular monster back into a cage.
390
Taggart @taggart-tech.com · 7h
I don't talk about this a lot but I have struggled my whole life with this culture's idea of masculinity. Like I'm fine with my personal gender expression, but it actually bothers me that I am in the same bucket as, for lack of a better term, bros.
1100
Taggart @taggart-tech.com · 7h
And if more of your energy is going into explaining why *you* aren't the problem than actively helping, guess what?
180
Taggart @taggart-tech.com · 7h
Taking a break from the normal cybers to say this: Men, if you aren't **actively** holding your peers accountable for SA, misogyny, or any other form of discrimination/abuse of women, you are the problem too.
1254
Taggart @taggart-tech.com · 20h
This was exactly my first thought
020
Taggart @taggart-tech.com · 23h
I stg 10 minutes with pen on paper gets more and better thinking out of me than a whole damn day in front of a keyboard getting yanked this way and that by the notification blitz we've created for ourselves.
060
Reposted by Taggart
IFIN @ifin-intel.org · 29/09/2026
If you're involved in vulnerability management/VulnOps, the last several months have been overwhelming. But take heart: there is a path forward, despite the madness surrounding us.
ifin-intel.org
Finding the Signal in the Vulnerability Noise | IFIN
The flood of new CVEs can make it hard to know what matters. But there are tools to help find our way.
086
Reposted by Taggart
IFIN @ifin-intel.org · 29/09/2026
We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed. ifin.network/t/multi... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Multiple Citrix Netscaler 0-Days Exploited
Last Updated: 2026-09-29T14:53:55Z (UTC) What’s Happening Citrix has disclosed 8 critical CVEs. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 There’s also an associated blog post. Affected Versions Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23 Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279 Indicato...
285
Taggart @taggart-tech.com · 29/09/2026
This NVidia OpenShell thing is wild insofar as I've never seen a GitHub repo get so much press. That's what the "Open Agent Safety Platform" is. Well that and some proprietary gear that it's "optimized" for.
000
Taggart @taggart-tech.com · 28/09/2026
I watched this movie recently and had to just sit and think about how good it was for a while. Especially as an American, there are parts of the post-WWII story in Japan that you're not easily exposed to, and that really mattered.
010
Taggart @taggart-tech.com · 28/09/2026
Lots of reasons this is true, with "Southern California" being the biggest among them. But yeah, even with being pretty careful, summers are b r u t a l.
110
Taggart @taggart-tech.com · 28/09/2026
My electric bill far outstrips my car payment.
230
Reposted by Taggart
Taggart @taggart-tech.com · 28/09/2026
Someone on here is accusing me of breaching confidentiality and lying about it, without evidence. I was provided with reliable Intel without restrictions, but from a source that didn't want to be named. That is consistent with TLP and CTI/journalism standards.
121
Taggart @taggart-tech.com · 28/09/2026
Someone on here is accusing me of breaching confidentiality and lying about it, without evidence. I was provided with reliable Intel without restrictions, but from a source that didn't want to be named. That is consistent with TLP and CTI/journalism standards.
121
Taggart @taggart-tech.com · 28/09/2026
Since I apparently have to make this clear: I'm not advocating for breaching TLP; I'm advocating defaulting to disclosure. Also, confidential sourcing and TLP are compatible, and even mentioned in the TLP docs. Confidential sourcing is not the same as "breaching" TLP.
170
Taggart @taggart-tech.com · 28/09/2026
Some of the IoCs were given freely, but provided by a source that prefers to remain anonymous. The attribution is not covered by TLP. That is a source protection practice common to both journalism and CTI.
010
Taggart @taggart-tech.com · 28/09/2026
You seem to be intentionally confusing advocating for TLP: CLEAR with breaking confidentiality.
010
Taggart @taggart-tech.com · 28/09/2026
And that's just the vulnerability itself, to say nothing of the observables of ongoing attacks. In that situation, cat's out of the bag. and keeping them confidential is dangerous.
010
Taggart @taggart-tech.com · 28/09/2026
First, I did not break TLP. Not sure why you think I did. Everything published was published elsewhere or provided as TLP:CLEAR. Second, that's simply not backed by evidence. When workarounds or patches are available, early disclosure always benefits defenders.
110
Reposted by Taggart
Taggart @taggart-tech.com · 27/09/2026
Today is very effectively making the argument for us at IFIN that TLP:CLEAR should be the *default*, and only extremely sensitive intelligence should be withheld. Active exploitation is not a reason to withhold, given the fact that more information always advantages defenders.
0114
Reposted by Taggart
Nicholas Grossman @nicholasgrossman.bsky.social · 27/09/2026
What's a good way to visualize how the AI boom/bubble is propping up the economy? Ah, thanks.
12706189
Taggart @taggart-tech.com · 27/09/2026
Today is very effectively making the argument for us at IFIN that TLP:CLEAR should be the *default*, and only extremely sensitive intelligence should be withheld. Active exploitation is not a reason to withhold, given the fact that more information always advantages defenders.
0114
Reposted by Taggart
IFIN @ifin-intel.org · 27/09/2026
Patches are available and updated versions are now listed.
073
Taggart @taggart-tech.com · 27/09/2026
Updated with the latest from Citrix.
030
Taggart @taggart-tech.com · 27/09/2026
Literally as I'm typing this Citrix releases their advisory: support.citrix.com/support-home...
support.citrix.com
Loading...
040
Taggart @taggart-tech.com · 27/09/2026
I have seen this "writeup" of the new Citrix 0-days but there's no correlation with anything, no sourcing (Citrix has not released a patch to diff), so I'm very skeptical.
sh3llc0d3.com
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...
220
Reposted by Taggart
Joe Uchill @joeuchill.bsky.social · 27/09/2026
Finally, we can burn sources and methods at speed.
0157
Reposted by Taggart
Sweetbabette @sweetbabette.bsky.social · 27/09/2026
The Phillies organization should go to a late night cheesesteak place and interview the first 5 people in line wearing Phillies gear and put the most specifically hurtful one in the locker room pre-game tomorrow
712524
Taggart @taggart-tech.com · 27/09/2026
Finally got enough on this to publish. Developing story.
070
Reposted by Taggart
Sarah McAnulty, Ph.D. @sarahmackattack.bsky.social · 25/09/2026
If you care about keeping the Academy of Natural Sciences open to the public in Philadelphia, I need you to read and share this thread. Trish Wellenbach was sent from the mayor's office to oversee the Academy of Natural sciences situation. She needs to hear from us. Here comes the action item:
15549483
Reposted by Taggart
Gwen C. Katz @gwenckatz.bsky.social · 25/09/2026
Fuck ChatGPT flyers. The future is broadsheets.
A crowded broadsheet with way too many fonts. It says:
Forget ChatGPT Flyers
Say it with 
Broadsheets
Unlimited fonts
Stretch them
Or cram a really long sentence into one line for no good reason
No whitespace
Mix capital and lowercase
Pointing hands
(They're called manicules!)
Don't be left behind
Broadsheets are the future
203188035331
Taggart @taggart-tech.com · 25/09/2026
Do you know them?
mttagg.art
Learn the Stars
010
Taggart @taggart-tech.com · 24/09/2026
This looks to me like maybe an account takeover on your dev account?
101
Reposted by Taggart
Clara Jeffery @clarajeffery.bsky.social · 24/09/2026
We just dropped a bombshell investigation into ChatGPT's role in the Tumbler Ridge mass shooting. Incredible reporting from @markfollman.bsky.social that will have far-reaching effects...hopefully: www.motherjones.com/media/2026/0...
motherjones.com
ChatGPT helped the Tumbler Ridge school shooter focus on guns, tactics, and terror, our investigation reveals
OpenAI’s chatbot fed the shooter’s violent fantasies and planning up to the massacre.
271467748
Reposted by Taggart
Preeti Chhibber @runwithskizzers.bsky.social · 24/09/2026
all these people sound like this:
62261531
Taggart @taggart-tech.com · 24/09/2026
Whenever an AI company tells you about security, believe the opposite.
mouse.dev
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB | Mouse
I asked Muse to archive the files it could see and send them to my Google Drive. It did.
14822
Taggart @taggart-tech.com · 24/09/2026
Ooof, very sort of. Nowadays it's much more mechanical. The certs that still care about good manual reports are few and far between.
010
Reposted by Taggart
Rowdy @r0wdy.sk33t.expert · 24/09/2026
A neat twist to CTF competitions could be something like capturing the flag(or flags) isn’t how you win it’s teaching someone else how to capture it
5113
Taggart @taggart-tech.com · 24/09/2026
There have been some with prizes awarded for the best writeups and I 100% believe that is dope.
130
Reposted by Taggart
Taggart @taggart-tech.com · 23/09/2026
You know, if tech companies are looking for a, uh, less *problematic* non-profit to fund, I have some thoughts...
ifin-intel.org
IFIN | The Independent Federated Intelligence Network
A not-for-profit organization dedicated to the teaching of best practices in cyber threat intelligence, and the mutual sharing of timely, actionable, and relevant intelligence among the community.
0104
Taggart @taggart-tech.com · 23/09/2026
Harnesses I use routinely make errors in naming my home directory. Imagine a miss on a target domain.
140
Reposted by Taggart
JiSe @jise.bsky.social · 23/09/2026
Another thing that worries me about these is that as we have seen, there is really no easy way to make sure something you sack an AI to do, will be done within scope and safely. Preparing people to just go "Hey Claude, hack this box" will inevitably lead into some horrible scenarios when done IRL.
111
Reposted by Taggart
Taggart @taggart-tech.com · 23/09/2026
Making this about throwing tokens at a flag mistakes the flag for the value of a CTF, rather than the path that leads to the flag.
151
Reposted by Taggart
Taggart @taggart-tech.com · 23/09/2026
Sorry, still annoyed about this, especially from someone I used to really look up to. The entire point of a CTF is to build skill—the very skill, by the way, necessary to verify any model output in a given field. Without knowing the stuff yourself, you can never know whether the model got it right.
182
Taggart @taggart-tech.com · 23/09/2026
Making this about throwing tokens at a flag mistakes the flag for the value of a CTF, rather than the path that leads to the flag.
151
Taggart @taggart-tech.com · 23/09/2026
Sorry, still annoyed about this, especially from someone I used to really look up to. The entire point of a CTF is to build skill—the very skill, by the way, necessary to verify any model output in a given field. Without knowing the stuff yourself, you can never know whether the model got it right.
182