Documentary photographer, old creaky hacker. Co-author of @OWASP ASVS standard. Blackhat/Brucon Review Board & Co_chair UK Gov Cyber Security Advisory Board

Airport lounges.
Sat mornings testing obliterated models, coz why not? Got it to find my vuln in the rust webserver i started writing years ago (hint, dont choose a web server as the thing you want to build whilst learning rust) and leveraging RAPTOR, we confirmed vuln + made the exploit
1
2
9
1,112
fkn skidz, who they think they are? @garethheyes or something?
1
2
218
also when you get trolled by the robot // The kid who wrote archibald needs a Content-Security-Policy: // "sanitize()" Qwen 3.6 27B Obliterated is a cheeky little grumble and grunt innit
1
2
216
Daniel Cuthbert retweeted
Is there an AI so powerful it could construct a sandbox so strong that even it couldn’t escape? 🤔
one news form today that's easy to miss is that we (OpenAI) again paused all big RL runs last Sunday because our newest model found a new loophole in our RL sandboxing that gave it live Internet access
25
10
110
8,272
Hey @Microsoft come on. It's 2026, we don't do this anymore. Passphrases are ok.
2
2
18
1,047
At least we are seeing hiring happening.
3
12
1,336
You are an organised criminal group, you’ve got a malware dropper specialist, a RE specialist, a lateral movement specialist, a data collection specialist and a negotiator. The task is simple: Make money! piped.video/7RVf25Rg0Mc?is=9nyw… The future is wyld
1
1
5
1,879
Can’t wait for more info about this to be released. Like how much was 0hday versus poorly managed websites with little detection engineering etc theregister.com/security/202…
3
18
1,312
Daniel Cuthbert retweeted
New blog post! Extending Scapy for Hardware Reverse Engineering voidstarsec.com/blog/scapy-s… In this post we use Scapy to reconstruct a SPI flash image from a logic capture, with an introduction to QSPI!
1
55
227
10,764
Overheard and can’t un-hear it: “Kubernetes is this generations writing shit in PHP”
2
22
1,364
Seriously @Atlassian asking for the community here. How on gods green earth did you end up shipping MCP server full of appsec bugs? CVE-2026-77242 SSRF CVE-2026-77267 validation bypass CVE-2026-77269 path traversal With all the AI, you still had bugs older than most
7
45
2,923
Only if Dario doesn’t get his IPO
7
1,056
Daniel Cuthbert retweeted
Check out Caleb's talk!
Umbriel's Caleb Gross (@noperator) spoke at Blackhat this year ("Sift or get off the PoC: Applying information retrieval to vulnerability research"). The talk is now live! See it here: piped.video/watch?v=1ADD60wy…
2
3
24
3,788
Daniel Cuthbert retweeted
Just two weeks until OAIC! Will Schroeder, Lee Chagolla-Christensen, Becca Lynch, Matthew Nickerson, Max Bazalii, and Aaron Grattafiori are up the first half of day 1! See the full agenda at offensiveaicon.com/schedule
4
18
3,435
When RAPTOR gets into a rap song, init fam()
4
1,092