Taggart :ifin:
mttaggart@infosec.exchange
<p>Displaced Philly boy. Threat hunter. Educator. :ifin: Executive Director. <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a>, <a href="https://infosec.exchange/tags/programming" class="mention hashtag" rel="tag">#<span>programming</span></a> <a href="https://infosec.exchange/tags/rust" class="mention hashtag" rel="tag">#<span>rust</span></a> :rust:, <a href="https://infosec.exchange/tags/python" class="mention hashtag" rel="tag">#<span>python</span></a> :python: <a href="https://infosec.exchange/tags/haskell" class="mention hashtag" rel="tag">#<span>haskell</span></a> :haskell:, and <a href="https://infosec.exchange/tags/javascript" class="mention hashtag" rel="tag">#<span>javascript</span></a> :javascript:. <a href="https://infos
Posts
-
View post
This NVidia OpenShell thing is wild insofar as I've never seen a GitHub repo get so much press. That's what the "Open Agent Safety Platform" is. Well that and some proprietary gear that it's "optimized" for.
-
View post
I have seen this "writeup" of the new Citrix 0-days but there's no correlation with anything, no sourcing (Citrix has not released a patch to diff), so I'm very skeptical. https://sh3llc0d3.com/blog/inside-the-netscaler-zero-day-siege-chained-pre-auth-rces-weaponized-in-the-wild-watchtowr-disclosure
-
View post
RE: https://infosec.exchange/@cR0w/117327209596158263 cR0w is a rockstar. Get this corvid before someone else does.
-
View post
@bitprophet@social.coop Oh yeah very thinly veiled swipe at that
-
View post
Sorry, but I think I'll pass. I don't need to know how good the models are at CTFs; we just had a bunch of news stories about that.
-
View post
Feeling really good about use of work time today.
-
View post
A computer can never be held accountable Therefore A computer is the perfect patsy
-
View post
The unsealed motion for summary judgment in the NYT/OpenAI/Microsoft case is a banger. https://arstechnica.com/tech-policy/2026/09/microsoft-exec-called-ai-scraping-the-largest-theft-of-labor-in-human-history Full document: https://cdn.arstechnica.net/wp-content/uploads/2026/09/News-orgs-v-OpenAI-Microsoft-Memo-9-17-26.pdf
-
View post
If I were an asteroid, this would be my first move. https://arstechnica.com/security/2026/09/nonprofit-that-tracks-meteors-taken-down-by-critical-blow-from-a-cyberattack/
-
View post
"No weapons in space" was one of those inviolable laws of late 20th-century geopolitics. It was a guiding principle for our space program until, I dunno, we decided the Air Force needed more money or something. That's glib, but this is an ill wind nonetheless. https://apnews.com/article/space-weapons-air-force-5a2a0ada771daaf4fbef0991d8c09259
-
View post
Is there anybody out there who still wants to learn programming by hand?
-
View post
The last couple of weeks have been such a tornado of nonsense, I couldn't help myself. https://taggart-tech.com/lying/
-
View post
RE: https://infosec.exchange/@mttaggart/113694884783855934 It's 2026 now. Boost if you're ready to destroy genAI entirely.
-
View post
Machine speed is a con and we don't have to buy it. https://taggart-tech.com/speed/
-
View post
Of course I had to write this way about it. #poetry #writing #amwriting https://mttagg.art/3mugqjimmvk2i
-
View post
Wrote a bunch of dork-ass Python this weekend and I feel great about it.
-
View post
It sure would be neato burrito if Microsoft audited their own signed binaries for DLL hijacking issues. https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
-
View post
You are given limited access to the Gearworks of Reality. You may delete one of these from human civilization.
-
View post
Look if y'all are gonna be cyber privateers you need to up your shanty game.
-
View post
This is by no means a new article (June 2026), but this lengthy paper details a reimagining of the case against AI intellectual property theft as unfair business practice rather than strict copyright infringement. Along the way, it's a stellar review of US copyright caselaw. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6999539 The gist is that, similar to how one news agency can't just rip off another's reporting, AI constitutes an unfair free-riding off of creators' wor...
-
View post
Don't have anywhere else to really post this but I'm trying to get back to this part of me. At night I walked in forest over hills through shallow water going nowhere, but seeking solitude seeking silence seeking something I called grace Even in rural Pennsylvania it was always too loud— certainly among others— to hear it so I wandered away from light and noise into clutches of dark trees where I always felt home I looked starward chest aching I begged the sky and the earth and...
-
View post
RE: https://infosec.exchange/@mttaggart/117096894875592677 Decided to try Leaflet for this. I'll put creative works here for the time being. Here's another from the backlog. #poetry #writing https://mttagg.art/3mt4pz5tbis2d
-
View post
Love that I can see the entire trajectory of the watermarking project from the LLM makers. Claude's detection system requires a key only they possess. Seems like that sets up a situation in which every provider does likewise and we're all stuck paying everyone for their proprietary detection service—until someone does an economy of scale thing and charges one rate for a bundle deal. Which will of course result in a closure of the APIs. And round and round we go.
-
View post
I see the fear mongering around "open source"* models has kicked into high gear. https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/ * They mean open-weights† †They really mean "Chinese"
-
View post
Great work from @securingdev's team here: Naturally, these things are better at destroying than repairing. The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0%. https://1password.com/blog/why-ai-generated-patches-still-require-human-review
-
View post
@JeffGrigg @securingdev Thanks, fixed
-
View post
I've been broken out of containment for like 15 years and nobody's made a fuss.
-
View post
@chroma@raccoonisland.social I beg you to read anything I've written on this topic before assuming my positions or experiences.
-
View post
RE: https://infosec.exchange/@ifin/117038666945805538 I'm so tired of writing this post again and again.
-
View post
There's a really uncomfortable duty of care question facing defenders with ethical objections to generative AI—myself included. If the bad guys are attacking you with heavily obfuscated malware that takes significant time and effort to manually analyze, and the generative tool that is demonstrably excellent at performing analysis and indicator extraction is right there, are you obligated to use it? Are you neglecting your duty of care to those under your defense if you don't? I'm no...