@dcuthberti
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
Documentary photographer, old creaky hacker. Co-author of @OWASP ASVS standard. Blackhat/Brucon Review Board & Co_chair UK Gov Cyber Security Advisory Board
Airport lounges.
Joined April 2008
- Tweets17.6K
- Following2K
- Followers33.6K
- Likes45.8K
Proof being a CISO is stressful, Darrin quit and decided to drive his Land Rover all over one of the most spectacular countries I’ve ever been to: Namibia
youtu.be/RYGsa9c7PzM?is=oa_U…
So if you like the wilderness and stuff, give it a watch and subscribe and help an ex-CISO recover
As if tech bros couldn’t get more cringe…
vanityfair.com/story/gouging…
What would @dieworkwear think?
Sat mornings testing obliterated models, coz why not?
Got it to find my vuln in the rust webserver i started writing years ago (hint, dont choose a web server as the thing you want to build whilst learning rust) and leveraging RAPTOR, we confirmed vuln + made the exploit
fkn skidz, who they think they are? @garethheyes or something?
Daniel Cuthbert retweeted
Is there an AI so powerful it could construct a sandbox so strong that even it couldn’t escape? 🤔
Hey @Microsoft come on. It's 2026, we don't do this anymore. Passphrases are ok.
You are an organised criminal group, you’ve got a malware dropper specialist, a RE specialist, a lateral movement specialist, a data collection specialist and a negotiator. The task is simple:
Make money!
youtu.be/7RVf25Rg0Mc?is=9nyw…
The future is wyld
I’ve ignored the Jev hot takes, mostly coz they are crap but not this one by @4rcherhume
archerhume.com/posts/jevs-ar…
Such a solid take and good use of RE’ing the APIs this way.
Can’t wait for more info about this to be released. Like how much was 0hday versus poorly managed websites with little detection engineering etc
theregister.com/security/202…
Daniel Cuthbert retweeted
New blog post!
Extending Scapy for Hardware Reverse Engineering
voidstarsec.com/blog/scapy-s…
In this post we use Scapy to reconstruct a SPI flash image from a logic capture, with an introduction to QSPI!
30 years old and this is still so banging
youtu.be/1lE0KKV-GMo?is=yRsw…
Seriously @Atlassian asking for the community here. How on gods green earth did you end up shipping MCP server full of appsec bugs?
CVE-2026-77242 SSRF
CVE-2026-77267 validation bypass
CVE-2026-77269 path traversal
With all the AI, you still had bugs older than most
Check out Caleb's talk!
Umbriel's Caleb Gross (@noperator) spoke at Blackhat this year ("Sift or get off the PoC: Applying information retrieval to vulnerability research"). The talk is now live! See it here: youtube.com/watch?v=1ADD60wy…