Taggart
@taggart-tech.com
@mttaggart@infosec.exchange. Displaced Philly boy. Executive Director of @ifin-intel.org. Threat hunter. Educator. Dad. General in the AI Resistance. taggartinstitute.org wtfbins.wtf linktr.ee/mttaggart
I'm too tired for even the "What can possibly go wrong?" of it all. Every day they build new ways to take your agency from you. Every day they add to the house of cards that can only end one way.
Python Workers are now generally available
Python Workers allow developers to run Python web frameworks and AI orchestration libraries natively in the Cloudflare Workers runtime. You can seamlessly integrate with Cloudflare's ecosystem including D1, R2, and Workers AI without writing any JavaScript glue code.
blog.cloudflare.com
if you don't think humanistic learning has value in its own right, no amount of instrumentalization is going to save it that epochal decline coincided with the hegemony of the "employable skills" pitch, including earnings data and all the trimmings, ought to have taught us that
My whole career the Humanities seem to have been curled up in a defensive crouch trying to justify our meaning/existence. At times it has even seemed a productive thought exercise, but I think generally whatever body has demanded the justification is not really open to being persuaded of anything.
A computer can never be held accountable Therefore A computer is the perfect patsy
There's a part of the 3 Body Problem series where technology shifts to all metal because of a lack of plastics and like, yes give me the stainless steel streamline moderne future we were promised in the 30s
The "everything is oil" part of the coming global disruption hasn't sunk in for people yet. The price of gasoline in your car will be one of the smallest effects.
Rust maintainers are targeted (again), but good news: the same defenses as always apply. ifin.network/t/rust-... #ThreatIntel #ThreatIntelligence #IFIN #Rustlang
Rust Package Maintainers Targeted with Social Engineering, Repo Takeover
Last Updated: 2026-09-18T12:35:00Z (UTC) What’s Happening According to the Rust language security response working group, maintainers of rust-lang (the repo comprising the Rust language itself) and popular packages (crates) are being targeted by social engineering attacks intended to compromise the repository. Per the post: A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that’s used as a vector to either g...
ifin.network
Incredibly goofy work here. Patched now, but you could pwn Claude and Codex thanks to confusion between commit hashes and branch names. Microsoft hasn't patched.
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent.
air.security
The unsealed motion for summary judgment in the NYT/OpenAI/Microsoft case is a banger. arstechnica.com/tech... Full document: cdn.arstechnica.net/...
Microsoft exec called AI scraping the “largest theft of labor in human history”
Microsoft, OpenAI emails reveal fear of AI “doom loop” killing news orgs.
arstechnica.com
Got a #cybersecurity question? Don't ask AI. Ask people who know. Join us at https://ifin.network.
IFIN
The Independent Federated Intelligence Network
ifin.network
Being told that you will be “left behind” by not giving untold amounts of personal and institutional money to the Effective Altruists to buy their AI tokens as a way to accomplish a better future is something that someone says who wants to personally benefit from a narrow future for the powerful.
longtermism is so repugnant that I hesitate to address it on its own terms but: on its own terms this shit is clearly wrong. the best way *now* to encourage a happy future for umptillion beings who use technology we can't imagine is to make the current world more just for everyone.
My friends, I have spent months assessing "AI security" products, especially ones that claim to prevent jailbreaking, prompt injection, etc. Here's what I know:
If I were an asteroid, this would be my first move.
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Group plans to be largely out of commission for several weeks.
arstechnica.com
My friends, I have spent months assessing "AI security" products, especially ones that claim to prevent jailbreaking, prompt injection, etc. Here's what I know:
If you need help analyzing a sample or a second pair of eyes, drop IFIN a line. #ThreatIntelIsMutualAid
Based on a community tip (we love those!), we discovered yet another malware family that's bringing its own Python interpreter—and a few other tricks. Bring-Your-Own-Python is *so hot right now* ifin.network/t/quick... #ThreatIntel #ThreatIntelligence #IFIN
Based on a community tip (we love those!), we discovered yet another malware family that's bringing its own Python interpreter—and a few other tricks. Bring-Your-Own-Python is *so hot right now* ifin.network/t/quick... #ThreatIntel #ThreatIntelligence #IFIN
QuickFix: Yet Another Bring-Your-Own-Python Payload
Last Updated: 2026-09-16T14:53:57Z (UTC) What’s Happening TL;DR: `fileupdates.blob.core.windows[.]net is hosting “QuickFix,”, a new-ish installer file with PowerShell that installs its own Python interpreter, then activates a light C2 beacon for Python commands send via JSON. The detection opportunity is Python executing outside of expected directories. This was a tip from Fedi and turned into a really fun investigation. The tipper was surprised that Microsoft even allowed that blob storage...
ifin.network
The U.S. AI industry is being run by a batshit rationalist sex cult, and no, I am not being hyperbolic - they’re genuinely Like That:
The last couple of weeks have been such a tornado of nonsense, I couldn't help myself.
Everone Is Lying To You For Money
The recent cyber incidents required a pivot from the frontier AI labs. The pivot? Lie and distract.
taggart-tech.com
I hope everybody realises just how openly the fossil fuel companies are talking about how much the data centre boom directly benefits them www.datacenterdynamics.com/en/videos/dc...
I didn't add a "What you can do" section to this piece because for most folks, the best thing you can do is not believe these charlatans. But if you're in a position where you *must* use or build with these tools...
The last couple of weeks have been such a tornado of nonsense, I couldn't help myself.
"No weapons in space" was one of those inviolable laws of late 20th-century geopolitics. It was a guiding principle for our space program until, I dunno, we decided the Air Force needed more money or something. That's glib, but this is an ill wind nonetheless. apnews.com/article/s...
The last couple of weeks have been such a tornado of nonsense, I couldn't help myself.
Everone Is Lying To You For Money
The recent cyber incidents required a pivot from the frontier AI labs. The pivot? Lie and distract.
taggart-tech.com
I am incredibly excited for this project. We take the stewardship part of maintaining these lists very seriously. Our goal is for IFIN to become a trusted source of independent, vendor-agnostic threat intelligence and defense techniques.
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. ifin-intel.org/blog/... #ThreatIntel #ThreatIntelligence #TIIMA
> Lighthouses are present in half of all 20,000 stories generated for this experiment. Turns out the models are not just awful storytellers; they're getting worse. arxiv.org/html/2605....
I beseech you all to read this incredible letter about an aquarium in impeccable Kid Negotiation Tactics
Another classic letter from this family.
One of our first lists is the cryptocurrency RPC Nodes lists. You want to block these right now to neutralized #Etherhiding attacks! lists.ifin.network/lists/rpc-no...
RPC Nodes - IFIN Lists
A curated collection of long-term block lists and hunting targets for all organizations, along with documentation and explanations.
lists.ifin.network
I am incredibly excited for this project. We take the stewardship part of maintaining these lists very seriously. Our goal is for IFIN to become a trusted source of independent, vendor-agnostic threat intelligence and defense techniques.
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. ifin-intel.org/blog/... #ThreatIntel #ThreatIntelligence #TIIMA
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. ifin-intel.org/blog/... #ThreatIntel #ThreatIntelligence #TIIMA
Announcing IFIN Lists | IFIN
IFIN Lists is a project to build a well curated, community driven set of permanent block lists for all to use.
ifin-intel.org