Hacker | Pilot | Lifter | OSCE3, CISSP, CCNP | Top 20 Hack the Box | World’s first Certified Offensive AI Expert (COAE) | reviews & writeups | meme magic 🐸

NC, United States
The Spacecraft Hacker's Handbook published by No Starch Press and written by Andrzej Olchawa and Milenko Starcik is ambitious, practical, and deeply rewarding. It takes you from knowing almost nothing about space missions to having intelligent conversations about their architecture and enough methodology to conduct your own security research. I came in with no real understanding of how spacecraft, ground stations, mission control systems, or satellite terminals worked. I finished the book with a working mental model of those systems and a clear sense of where I could keep learning on my own. That is a significant achievement in a 344-page book. The authors compress what feels like an entire introductory course into an information-dense technical survey without getting stuck in the mathematics of signals or orbital mechanics. The most useful lesson is how many boundaries exist across a space system, and how those boundaries interact. Ground stations, mission control software, flight software, communications protocols, user terminals, and navigation receivers each create opportunities for research. The only thing likely to slow some readers down is also one of the book's biggest strengths: it covers a broad range of concepts in a relatively small page count, which makes the reading technically dense. That compression is part of why it works. An 8.5/10 feels right for this fantastic introduction to space security. What keeps it from a perfect score is largely the same thing that makes it worth reading. So many concepts in 344 pages that the book stays technically dense and may put off readers looking for a lighter introduction. More than once I photographed a dense page and passed it to ChatGPT to explain every abbreviation before I could move on. Check at the full review on my website: jacobkrell.com/writeups/book…
9
36
263
8,818
Jacob Krell retweeted
The Spacecraft Hacker’s Handbook authors Andrzej Olchawa (@0x4ndy) and Milenko Starcik showed @davidbombal how patched web vulnerabilities in mission control software could expose files and send commands to a spacecraft simulator. Watch the interview: piped.video/watch?v=v0wB8Zal… and preorder the book! nostarch.com/spacecraft-hack…
13
45
4,102
I had a chance to write for Dark Reading on the OpenAI Hugging Face attack and the need for human in the loop and "fail close" deterministic control systems. Rules that agents can reason around following are not strong security controls.
AI Model Rules Are Not Security Controls: bit.ly/4i5g1U1 Commentary by Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs
2
5
21
1,039
My full review for Heavy Wizardry 101 By David Martinez Oliveira (Pico) and published by No Starch Press is now live: jacobkrell.com/writeups/book… Heavy Wizardry 101 earns its hardcover. Pico takes you from foundational computer architecture through C and assembly exploit development, ending with a fully functional assembly worm that propagates across x86_64, ARM, MIPS, and RISC-V. The wizard theming runs deeper than decoration. Chapter titles like "Spell of the Binary Oracle" and "Veil of Ash" match the actual progression from apprentice to practitioner, and by the final chapters I genuinely felt like one. This is the only No Starch Press book on my shelf with a hardcover, and the production quality matches the content. The technical depth and usefulness of what Pico covers made me feel like it earned that printing. 464 pages of C and assembly exploit development across four architectures is a lot of material, and the physical book holds up as a reference I'll keep reaching for. I came into this with solid x86 assembly experience and limited exposure to the other architectures. The book's approach of implementing every concept across all four forced a kind of understanding I didn't expect. Instead of memorizing opcodes and register names per Instruction Set Architecture (ISA), I started recognizing the principles that carry across all of them. That shift from architecture-specific memorization to first-principles fluency is the most valuable thing I took from this book. The trade-off is density. Pico does not hold your hand. He expects you to parse assembly, understand basic systems concepts, and keep pace with substantial blocks of code. There were stretches where I was reading more code than I fully absorbed in a single pass. The sheer volume of assembly across four architectures is tough to get through at times, but working that close to the hardware, across that many ISAs, is exactly what makes you feel like a wizard by the end. The title is fitting. 9/10. The only thing keeping it from a perfect score is that the density of cross-architecture assembly might be too intimidating for someone brand new to the subject. Everything else earned its place.
2
4
24
822
Jacob Krell retweeted
I uploaded a blog post to my website around this content for anyone that is interested. owlhacku.com/leveraging-frid…
Uploaded a recording of the presentation I gave at DEF CON 34 for the Mobile Hacking Community to my YouTube Channel. This isn't my live talk. Just me walking through the slides on camera. Hope you like it. piped.video/watch?v=7Db1fhZy…
1
10
33
2,366
I noticed there seemed to be a lot of security appliances getting hit lately. So I did some analytical research around it I hope you find interesting!
The devices built to protect your perimeter have become the most targeted way through it. In the latest analysis from Suzu Labs, Jacob Krell breaks down why firewalls, VPN gateways, and secure access appliances represent the single most consistently targeted category of enterprise tech: - 🚨 1 in 4 active exploits in 2026 stem from security & network infrastructure vendors, the highest proportion since the CISA KEV catalog launched. - 🎯 21 zero-days targeted security and networking products in 2025 alone (per Google’s Threat Intelligence Group). - 🔓 Ransomware Entry Points: 75 security appliance KEV entries are directly tied to known ransomware campaigns. - ⚡ Compressing Windows: Exploitation windows have shrunk from weeks to days, driven largely by state-aligned threat actors. Security appliances sit directly on the internet, hold elevated network trust, and run complex proprietary stacks that resist independent review. Treating these zero-days as standard "software bugs" rather than structural architectural risks leaves teams reacting to the same fire over and over. Read the full breakdown and methodological analysis on the Suzu Labs blog: na2.hubs.ly/H07gBh10
9
470
I Just finished Heavy Wizardry 101 from @nostarch, written by David Martínez Oliveira (Pic0). Full review coming soon. It was a fantastic read centered around C and assembly exploit development, with the book guiding you through the creation of an ASM worm across architectures like x86 and ARM. Going into it, I only had experience with x86 assembly, so it was a great introduction to the underlying principles of other assembly languages, how they differ, and how the same low-level concepts translate across architectures. I found it was certainly deserving of its hard cover printing.
3
2
22
581
I am extremely interested to see how many companies actually get included in this program. I have a feeling it will be very selective, similar to Project Glasswing, and end up excluding a lot of smaller teams. That said, I agree with the direction of the program. Cooperation between the private sector and the state is becoming increasingly important in cybersecurity, especially as offensive capabilities continue to advance.
America just authorized private companies to perform offensive cyber operations, and the next 60 days are critical. President Trump signed a National Security Presidential Memorandum (NSPM) allowing vetted private firms to target foreign cybercrime syndicates under federal oversight via the National Coordination Center (NCC). Critics are calling it “digital privateering,” but our CEO Mike Bell outlines why that framing misses the mark: - Not a free-for-all: No standing licenses or bounties. Every operation requires explicit, per-operation federal approval restricted strictly to criminal organizations. - The 60-day deadline: Private offensive capability exists; what is missing is the civilian oversight machinery. Operating procedures for vetting, targeting, and safeguards must be drafted now. - Accountability is key: Strict boundaries and mandatory reporting are required to prevent collateral damage and protect civil liberties. The private sector has the talent, now government must build the framework to direct it responsibly. Read Mike Bell’s full analysis on Suzu Labs: na2.hubs.ly/H07b2LL0 #Cybersecurity #OffensiveSecurity #CyberPolicy #NationalSecurity #PublicPrivatePartnership
4
12
804
Incredibly thankful to get to spend some time with @PhillipWylie over defcon weekend. Humbled to be able add the fantastic challenge coin he gave me to my collection.
2
17
618
After the Defcon CTF this year I have been seeing a lot of people talk about the "death of the CTF" because of agentic tooling. I had written a whitepaper on this back in march analyzing first blood times on Hack the Box machines. The writing has been on the wall for a while. It has, for at least a year or so, been about agentic engineering at the top level and not about cyber skills. suzulabs.com/suzu-labs-blog/…
5
15
76
5,513
Feels good to lift again after taking a week off for defcon. With how sore my legs and feet are, it certainly does not feel like a week off though haha
4
39
754
In b4 WiFi pineapples get banned now….
You do this shit it impacts all of us. Some folks want to cancel defcon permanently and give government a reason to label and target us as dangerous. Doing this shit on a plane causes safety risks and fear amongst passengers, hope these fuckers get on the no fly list and banned from defcon, but they are probably looking at jail time.
2
8
699