@dcuthbert

Documentary photographer, old creaky hacker. Co-author of @OWASP ASVS standard. Blackhat/Brucon Review Board & Co_chair UK Gov Cyber Security Advisory Board

Airport lounges.
Joined April 2008
Proof being a CISO is stressful, Darrin quit and decided to drive his Land Rover all over one of the most spectacular countries I’ve ever been to: Namibia youtu.be/RYGsa9c7PzM?is=oa_U… So if you like the wilderness and stuff, give it a watch and subscribe and help an ex-CISO recover
3
363
Sat mornings testing obliterated models, coz why not? Got it to find my vuln in the rust webserver i started writing years ago (hint, dont choose a web server as the thing you want to build whilst learning rust) and leveraging RAPTOR, we confirmed vuln + made the exploit
1
2
9
1,270
fkn skidz, who they think they are? @garethheyes or something?
1
2
228
also when you get trolled by the robot // The kid who wrote archibald needs a Content-Security-Policy: // "sanitize()" Qwen 3.6 27B Obliterated is a cheeky little grumble and grunt innit
1
2
227
Daniel Cuthbert retweeted
Is there an AI so powerful it could construct a sandbox so strong that even it couldn’t escape? 🤔
one news form today that's easy to miss is that we (OpenAI) again paused all big RL runs last Sunday because our newest model found a new loophole in our RL sandboxing that gave it live Internet access
27
13
1
123
10,214
Hey @Microsoft come on. It's 2026, we don't do this anymore. Passphrases are ok.
2
3
1
20
1,167
At least we are seeing hiring happening.
3
12
1,350
You are an organised criminal group, you’ve got a malware dropper specialist, a RE specialist, a lateral movement specialist, a data collection specialist and a negotiator. The task is simple: Make money! youtu.be/7RVf25Rg0Mc?is=9nyw… The future is wyld
1
1
5
1,884
Can’t wait for more info about this to be released. Like how much was 0hday versus poorly managed websites with little detection engineering etc theregister.com/security/202…
3
18
1,313
Daniel Cuthbert retweeted
New blog post! Extending Scapy for Hardware Reverse Engineering voidstarsec.com/blog/scapy-s… In this post we use Scapy to reconstruct a SPI flash image from a logic capture, with an introduction to QSPI!
1
56
228
10,794
Overheard and can’t un-hear it: “Kubernetes is this generations writing shit in PHP”
2
22
1,365
Seriously @Atlassian asking for the community here. How on gods green earth did you end up shipping MCP server full of appsec bugs? CVE-2026-77242 SSRF CVE-2026-77267 validation bypass CVE-2026-77269 path traversal With all the AI, you still had bugs older than most
7
1
45
2,927
Only if Dario doesn’t get his IPO
7
1,057
Daniel Cuthbert retweeted
Check out Caleb's talk!
Umbriel's Caleb Gross (@noperator) spoke at Blackhat this year ("Sift or get off the PoC: Applying information retrieval to vulnerability research"). The talk is now live! See it here: youtube.com/watch?v=1ADD60wy…
2
3
24
3,789