Coffeeing up for the day. If you see me, say hi. Repping the @ifin-intel.org tee that says “Threat intel is mutual aid” today because well, because threat intel is mutual aid. We’re an ecosystem of ecosystems, and the more sharing we do at our roots, the more our core and branches thrive.
Taggart
@taggart-tech.com
@mttaggart@infosec.exchange. Displaced Philly boy. Executive Director of @ifin-intel.org. Threat hunter. Educator. Dad. General in the AI Resistance. taggartinstitute.org wtfbins.wtf linktr.ee/mttaggart
We're thrilled to announce IFIN has achieved 501(c)(3) recognition! Now we can get down to business. ifin-intel.org/blog/... #IFIN
It's Official: We're a Recognized Non-Profit | IFIN
IFIN has achieved 501(c)(3) status. What this means for us, and for you.
ifin-intel.org
There's a really uncomfortable duty of care question facing defenders with ethical objections to generative AI—myself included.
I'm so tired of writing this post again and again.
Here's our coverage of the current ongoing keyv/cacheable NPM attack. We've included a list of known Ethereum RPC endpoints as indicators, since the malware looks up second stage data from that blockchain. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Here's our coverage of the current ongoing keyv/cacheable NPM attack. We've included a list of known Ethereum RPC endpoints as indicators, since the malware looks up second stage data from that blockchain. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Not-So-Mini Mini Shai-Hulud Attack Hits 400+ NPM Packages
Last Updated: 2026-08-04T18:28:08Z (UTC) What’s Happening Starting on the morning of 2026-08-04T07:00:00Z (UTC), multiple npm packages were impacted by a new worming package payload. The initial compromise of 11 packages appears to have wormed to at least 424, per Step Security. OpenSourceMalware and Socket are also covering the attack. Step provides differentiating context for this attack from prior ones: What sets this attack apart from the axios compromise of March 2026 is that ...
discourse.ifin.network
Folks fighting for ad blockers in your orgs: ifin-intel.org/blog/ad-bloc...
Just Deploy the Ad Blocker | IFIN
Enterprises sometimes shy away from free tools without support contracts. An ad blocker browser extension should not be one of them.
ifin-intel.org
By me at this.weekinsecurity.com: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person's crypto. This is the latest perfect example why you should use an ad-blocker.
This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea. Use a separate password manager.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
unit42.paloaltonetworks.com
Okay, I am going to tell a little story. It's one I have saved for the last couple years, almost nobody knows about it. But it lives in my heart. I don't know how others will feel about it, maybe something, maybe nothing. It's about the Uncanny X-Men. 1/
This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea. Use a separate password manager.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
unit42.paloaltonetworks.com
Unlike the Ontario wildfires, which were mostly burning in the woods, these fires have now burned through urban areas, making the smoke extra, extra toxic. Take the AQI warnings seriously this week, PNW neighbors.
Heads up, #Seattle...smoke from massive fires in Eastern Washington and Southern British Columbia will move into Western Washington starting early Monday, getting denser through Tuesday and Wednesday. Prepare for an extended period of degraded air quality. #wawx
You have to wonder how much of this there is out there. If what is found is only a fraction of reality, then the hype bubble is even more overinflated than we thought.
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.
research.jfrog.com
While this should be read as an institutional failure on behalf of the US government for failing to protect critical infrastructure, hats off to the DEF CON Franklin volunteers. This is the exact spirit in which IFIN was founded.
How volunteer cyber experts are helping protect rural water systems
A first-in-the-nation program is seeing promising results as it charts a path for supporting the U.S.’s most vulnerable infrastructure.
cybersecuritydive.com
At your next meal, take a second to think about the people working long hours in HOT 100° temps to put food on your table. They're not just statistics. They're real people who can't avoid the heat in an air conditioned house or office. #WeFeedYou
Happy Saturday! You might want to check if your Rails app needs a patch against this critical vuln.
CVE-2026-66066: KindaRails2Shell: RCE in Rails via Active Storage
Last Updated: 2026-08-01T19:50:50Z (UTC) CVSSv3: no cvss yet KindaRails2Shell Inspired by wp2shell, rails apps using ActiveStorage and default vips processor are vulnerable to Arbitrary File Read and Remote Code Execution via image upload from untrusted users. Kinda, because there are requirements, including very common configuration and default behaviors. No PoC from the research team or any technical details have been released yet, in order to give users time to patch. Versions Affected: ...
discourse.ifin.network
I’ve been thinking a lot about the thoughtlessness of AI writing. One of the many things that makes Melville’s prose so dazzling is the EXTEME rigor of the way he surprises, deepens and extends his metaphors and cultural touchstones. AI simply can’t, and not for the same reason that most of us can’t
Such a good passage.
LLMs can’t create surprising structure without heavy intervention because doing what’s expected is the telos of prompted next-token prediction. Even if you torture it into delivering out-of-band structure, there is no unity of motivated narrative consciousness to bind it together.
I've wanted to write this one since we started.
Sorry to disappoint, but there will be no IFIN Threat Actor Taxonomy. Here's why:
Ooof, Codeberg appears to be mega-down. HugOps to them. Both the main site and their Mastodon instance seem to have suffered a failure.
Good morning. We're observing an intensifying set of campaigns targeting credentials to facilitate data exfiltration and ransom. I've pulled some initial thoughts together over at @ifin-intel.org #threatintel #infosec #cybersecurity Cohesive writeup: discourse.ifin.network/t/newly-obse...
Newly-observed vishing/phishing campaign targeting retail/finance/fintech/more
On the threat intelligence side as well as the Very Concerned Customer side, seeing rising talk of an emergent campaign consistent with previous Com-related voice phishing. Domains include terms like ...
discourse.ifin.network
New packages are still being discovered with malicious payloads. Package adoption remains disabled.
Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
I'm too tired for outrage about Anthropic. They've been telling us they're reckless the whole time.
Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
New AUR Attack Prompts Adoption Lock
Last Updated: 2026-07-30T19:59:19Z (UTC) What’s Happening A new round of Arch User Repository malware has prompted the disabling of package adoption. The first package with confirmed malware appears to be openconnect-sso. User ysf has performed initial analysis of the payloads. Stage 1: AUR validator.malware (stage 1) · GitHub Stage 2: AUR validator.malware (stage2 agent linux x86_64) · GitHub Interestingly, many of the behaviors (especially Tor exfil) look similar to the last campaig...
discourse.ifin.network
We've compiled the latest information regarding the Minnesota water systems attacks. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Minnesota water system suffers a breach due to exposed access keys
Last Updated: 2026-07-30T00:16:10Z (UTC) What’s Happening On July 27, 2026, threat actors exploited a known vulnerability on a Rockwell Automation device and disrupted water treatment facilities in four counties in Minnesota, US. This activity is consistent with prior activity with Iran-aligned actors under the guise of “CyberAv3ngers,” although no direct evidence has yet emerged tying this activity to that group or any other. Actions The CVE used for initial access is CVE-2021-22681. This ...
discourse.ifin.network
We caught a sample of ACR Stealer and went deep on it. Lots of sophistication for "just" an infostealer. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
ACR Stealer: ClickFix, Etherhiding, and Stego, Oh My!
Last Updated: 2026-07-29T21:28:50Z (UTC) What’s Happening Earlier this month, Microsoft reported on ACR Stealer, a new campaign leveraging both Steganography and Etherhiding techniques for delivery. Yesterday, I caught myself a sample. Mine doesn’t have Etherhiding, but the rest makes for a fun exploration anyhow. Let’s dive in. ▶ Recommended Musical Accompaniment Disclaimer: A LLM assisted with deobfuscation/decryption of later stages. Stage 1: Initial Access via ClickFix While the infect...
discourse.ifin.network
Everyone focuses on models' use of emdashes, but honestly the way they use colons is as big a tell to me. They just love to slam the brakes on a sentence for dramatic effect.