Sign in

Silas Cutler

@silascutler.bsky.social
5.1K followers 522 following 148 posts

You may know me from your server logs. #Malware, Hacks, Internet Scanning, #CTI

PostsRepliesMedia
Reposted by Silas Cutler
Censys @censys.bsky.social · 27/08/2026
Censys ARC researcher @silascutler.bsky.social examines an exposed server containing Moobot botnet source code, active attack records, additional DoS tooling, and a fraudulent identity verification service. Full analysis of what the exposed directory revealed: bit.ly/3SUCPvz
052
Reposted by Silas Cutler
Raphael Mudge @raphaelmudge.bsky.social · 25/08/2026
Armitage and Metasploit Collaboration (NoVa Hackers - May 2011) I thought this one was lost. One of my earliest talks on the red team collaboration vision for Armitage and some reflection from using it in some 2011 exercises. www.youtube.com/watch?v=Mjr9...
youtube.com
Armitage and Metasploit Collaboration Raphael Mudge NoVa Hackers May 2011
YouTube video by Georgia Weidman
3113
Reposted by Silas Cutler
State of Statecraft Conference @what-is-sos.bsky.social · 13/08/2026
⏰ Just a few short days left to get your CFP in for 🆘 Volume II We exclusively showcase research into state-sponsored operations, demonstrate how the landscape is changing, and what sits on the horizon. Deadline is Aug. 14. Submit here 👉https://stateofstatecraft.com/cfp 🧵 1/N
146
Silas Cutler @silascutler.bsky.social · 07/07/2026
New #Boston conference just dropped
043
Silas Cutler @silascutler.bsky.social · 29/06/2026
The past few months have been incredible in the malware analysis space. AI has enabled a lot of folks to rapidly catch up in this space to where top researchers were about 5 years ago. The pace has wildly increased, but what I'm seeing set the leaders in this space is depth.
1166
Reposted by Silas Cutler
KM @sudox.bsky.social · 28/06/2026
081
Reposted by Silas Cutler
uberfoo.bsky.social @uberfoo.bsky.social · 22/06/2026
New Shitty Kitty V2 inventory available for pickup at #defcon34 at uberflux.com/product/UF-SK2 @defcon.bsky.social #defcon #badgelife
0236
Reposted by Silas Cutler
State of Statecraft Conference @what-is-sos.bsky.social · 18/06/2026
Registration and CFP for 🆘VOLUME II is officially OPEN! On October 22, 2026, we return to Brussels to showcase a day of community and discussions on the latest developments in state-sponsored operations and the actors & institutions that champion them.
2117
Silas Cutler @silascutler.bsky.social · 11/06/2026
🚗
110
Silas Cutler @silascutler.bsky.social · 10/06/2026
Harness, Scaffold, and the AI Agent Terms Worth Getting Right huggingface.co/blog/agent-glossary
040
Reposted by Silas Cutler
Dennis @dennisf.bsky.social · 01/05/2026
Start your weekend off right by watching the amazing @arianamirian.bsky.social talk about the way those gross text scams work and how she's working to disrupt their whole situation. youtu.be/5ArUiAjBoB8?...
youtu.be
Defeating Online Scams and Disrupting the Cybercrime Chain | Ariana Mirian
YouTube video by Decipher
021
Reposted by Silas Cutler
Megan Stifel @megans.bsky.social · 30/04/2026
Five years ago today Philip Reiner, Michael Daniel, John Davis, Jen Ellis Christopher Painter, Michael Phillips, Kemba Walden and I, together with the then tiny but mighty IST team and the essential input of the 60 plus Task Force participants, launched the #RansomwareTaskForce Report.
141
Reposted by Silas Cutler
PIVOTcon @pivotcon.bsky.social · 30/04/2026
Countdown is real ⌛️ Next week‼️ #ThreatResearch community gathers in Málaga 🇪🇸 Time to remind our PIVOTcon song: soundcloud.com/argonix/pivo... But watch out — it's a banger! #CTI #ThreatIntel #PIVOTcon26
media.tenor.com
a man in a white sweater is playing a keyboard with a vase of flowers in the background
ALT: a man in a white sweater is playing a keyboard with a vase of flowers in the background
098
Reposted by Silas Cutler
SentinelOne @sentinelone.com · 29/04/2026
LABScon 2026 Call for Papers is open. Sept 16–19, Scottsdale. Invite-only. Fifth year.
labscon.io
LABScon - Security Research in Real Time | LABScon
Join us September 16-19th for LABScon, an intimate, invite-only event for the top cybersecurity minds to gather, share cutting-edge research.
111
Reposted by Silas Cutler
Dennis @dennisf.bsky.social · 17/04/2026
Bay Area hackers GO SEE THIS MOVIE. Trust your boy. It’s great!
012
Reposted by Silas Cutler
The Bi of Hormuz @joshstein.bsky.social · 17/04/2026
One of the best pieces I’ve seen on the omnishambles of the FTC, by @masnick.com www.techdirt.com/2026/04/16/o...
techdirt.com
Oh Look, The MAGA FTC Built The Censorship Industrial Complex It Was Screaming About
We’ve been covering the Trump administration’s escalating campaign against NewsGuard for a while now. It started with the House Oversight Committee’s absurd investigation of the c…
17727
Reposted by Silas Cutler
—>realhackhistory.org @bsky.realhackhistory.org · 17/04/2026
I've been uploading #hacking magazines from #China, some of which have been removed for reasons I don't understand, to Internet Archive. This is a decent scan of an issue of Hacker Defence (or Hacker Defence Line?) from I think the early to mid 00s. #hacker #history archive.org/details/hack...
archive.org
Hacker Defence (黑客防线) : 黑客防线 : Free Download, Borrow, and Streaming : Internet Archive
Cannot work out the date associated with this issue but judging by the content it is probably early 00s.Hacker Line is the only Internet and computer...
162
Reposted by Silas Cutler
Zack Whittaker @zackwhittaker.com · 24/02/2026
NEW: The U.S. Treasury is sanctioning a Russian zero-day broker called Operation Zero. U.S. officials confirmed that Operation Zero was the company that bought exploits stolen by the former boss of U.S. defense contractor L3Harris Trenchant. Trenchant made hacking tools for the U.S. and its allies.
techcrunch.com
Treasury sanctions Russian zero-day broker accused of buying exploits stolen from U.S. defense contractor | TechCrunch
The U.S. Treasury announced it was imposing sanctions against a Russian broker of zero-day exploits, its founder and two affiliates, citing a threat to U.S. national security. Another affiliated zero-...
054
Silas Cutler @silascutler.bsky.social · 24/02/2026
Our blog at @Censys now has a proper RSS feed censys.com/feed (cc: @Feedly #GoogleReader)
183
Silas Cutler @silascutler.bsky.social · 24/02/2026
I've been seeing Vshell in #opendirs for a few years. With the recent attention, it was time to do a proper write-up on it: censys.com/blog/vshell
031
Silas Cutler @silascutler.bsky.social · 13/02/2026
Check out the agenda for [un]prompted . It was incredible to see what folks submitted and I'm excited to see everyone in March unpromptedcon.org
142
Silas Cutler @silascutler.bsky.social · 12/02/2026
#InternetOfPlants
060
Silas Cutler @silascutler.bsky.social · 10/02/2026
110
Reposted by Silas Cutler
SentinelLABS @sentinellabs.bsky.social · 29/01/2026
🔥 👀 New research from @morecoffeeplz.bsky.social and @silascutler.bsky.social on the "silent" AI network, a massive, unmanaged layer of open-source AI infrastructure operating in the shadows.
141
Reposted by Silas Cutler
Gabriel @morecoffeeplz.bsky.social · 29/01/2026
New research from @silascutler.bsky.social and myself. We tracked 175k exposed Ollama endpoints for nearly a year. Collected and analyzed custom models, sizes, quantizations, system prompts, and more.
131
Reposted by Silas Cutler
The Vertex Project @vertexproject.bsky.social · 21/01/2026
How do you track DDoS infrastructure when C2 servers rarely last a day? @vtx-savage.bsky.social and @silascutler.bsky.social are breaking down real-world DDoSia hunting using the Synapse-Censys Power-Up in our next webinar. vertex.link/events/censy...
054
Silas Cutler @silascutler.bsky.social · 20/01/2026
Join me next week at the @SANSInstitute #CTISummit in Arlington, VA where I'll be presenting on an operation against the infostealer #Rhadamanthys from early in its development. Register @ www.sans.org/u/1CtB
021
Reposted by Silas Cutler
The Vertex Project @vertexproject.bsky.social · 08/01/2026
We're hosting a webinar with @censys.bsky.social! Attackers can rotate infrastructure faster than threat hunters can keep up. Learn how defenders can pivot from indicators to infrastructure-centric intelligence. @vtx-savage.bsky.social + @silascutler.bsky.social vertex.link/events/censy...
053
Silas Cutler @silascutler.bsky.social · 06/01/2026
Come see me talk at the @SANSInstitute #CTISummit in Arlington, VA about the infostealer #Rhadamanthys during its early development. www.sans.org/u/1CtB
061
Reposted by Silas Cutler
Nick Chainey @nlfg.bsky.social · 29/12/2025
What a quote.
123145892
Silas Cutler @silascutler.bsky.social · 29/12/2025
Critical MongoDB Uninitialized Memory Disclosure Vulnerability [CVE-2025-14847] #MongoBleed From Censys scanning, we're seeing around 87,000 possibly vulnerable hosts censys.com/advisory/cve-2025-14847
010
Reposted by Silas Cutler
cje @cje.io · 27/12/2025
🚨🚨🚨 PATCH YO' MONGODB - PUBLIC POC AVAILABLE 🚨🚨🚨 m.cje.io/4q2Bi1Y
m.cje.io
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
142
Silas Cutler @silascutler.bsky.social · 26/12/2025
ColdFusion++ Christmas Campaign: Catching a Coordinated Callback Calamity www.labs.greynoise.io/grimoire/2025…
043
Silas Cutler @silascutler.bsky.social · 23/12/2025
Some unusual #CobaltStrike activity we observed at Censys before the holiday. At the start of December, we saw a spike in CobaltStrike in AS138415 followed by a matching spike two days after on AS133199. Report: censys.com/blog/recap-of-a-suspicio…
041
Silas Cutler @silascutler.bsky.social · 23/12/2025
I'm speaking at the @SANSInstitute #CTISummit on an operation against #Rhadamanthys years before #OperationEndgame. www.sans.org/u/1CtB
092
Reposted by Silas Cutler
Eric Geller @ericjgeller.com · 23/12/2025
Scoop: The lone employee behind CISA's Pre-Ransomware Notification Initiative resigned on Friday rather than take a forced reassignment to FEMA. CISA says PRNI will continue, but sources said David Stern's loss will be a major setback for it. My story: www.cybersecuritydive.com/news/cisa-ra...
7254129
Reposted by Silas Cutler
Robert Reich @rbreich.bsky.social · 22/12/2025
I’m old enough to remember when CBS News would never have surrendered to a demagogic president or any other politician. Remember Edward R. Murrow?
568128184471
Silas Cutler @silascutler.bsky.social · 19/12/2025
For anyone looking to optimize their news feeds, I've been using Miniflux (miniflux.app) as an RSS reader for the past few years. Recently I found it also works well for tracking newly released mechanical keyboards.
050
Reposted by Silas Cutler
Center for Cybersecurity Policy and Law @cyberseccenter.bsky.social · 19/12/2025
#DistillingCyber podcast is back with a special episode featuring Stacy O'Mara & Leonard Bailey. Tune in to explore whether offensive cyber operations should be used to counter cyber threats — if so, who should be authorized to carry them out? www.centerforcybersecuritypolicy.org/insights-and...
022
Silas Cutler @silascutler.bsky.social · 19/12/2025
unpromptedcon.org Con: 3-4 March 2026 CFP closes 28 January 2026, Submit at sessionize.com/unprompted-the-ai-se…
010
Silas Cutler @silascutler.bsky.social · 16/12/2025
NoName057(16) are still active despite last week's DOJ indictment. We looked into how their DDoSia platform works: censys.com/blog/ddosia-infrastructu…
010
Silas Cutler @silascutler.bsky.social · 03/12/2025
I'm sorry if I'm behind on replying to email. I'm at this point for reference
070
Reposted by Silas Cutler
andy jabbour @andyjabbour.bsky.social · 12/11/2025
New threat, Kazu ransomware. @ecrime.ch has new information on this threat actor. Kazu has claimed ~35 mostly public sector victims across Latin America, the Middle East, and Asia. 👀 cc @gate15.bsky.social @ransomwaresommelier.com @silascutler.bsky.social #cybersecurity #ransomware
023
Silas Cutler @silascutler.bsky.social · 06/11/2025
Part 2 of @DomainTools research is out: Inside the Great Firewall Part 2: Technical Infrastructure dti.domaintools.com/inside-the-grea…
041
Reposted by Silas Cutler
DistrictCon @districtcon.bsky.social · 31/10/2025
Interested in Jump The Wall? Applications close Nov 7 🔥 www.districtcon.org/jtw
034
Silas Cutler @silascutler.bsky.social · 30/10/2025
New from @DomainTools: Inside the Great Firewall Part 1: The Dump dti.domaintools.com/inside-the-grea…
061
Silas Cutler @silascutler.bsky.social · 30/10/2025
Really cool story about the developer of ZeroAccess - The ZeroAccess Developer and His Windows Kernel-Mode Debugger. r136a1.dev/2025/10/28/zeroaccess-de… www.youtube.com/@alexshort1643
030
Reposted by Silas Cutler
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 24/10/2025
It's getting close to being done - #BinYars a #YARA-X #BinaryNinja plugin! Still testing, but plan on open sourcing it for all to use. Shout out to Remco Sprooten for making this tool (also shown in the video) for quickly drafting Yara rules 💪 github.com/1337-42/Simp... Video: Part 1 of 2
173
Reposted by Silas Cutler
Jason Kikta @kikta.net · 24/10/2025
It did not. The reporter took the date on my original email about the planned malware release and assumed that the graphic was begun at the same time. I sketched out a rough version of that with the PAO in like 15 minutes of brainstorming on a whiteboard. She then sent it to the graphic contractor.
311921
Silas Cutler @silascutler.bsky.social · 24/10/2025
New drop from the Three Buddy Problem: Apple’s iOS forensics freeze, WhatsApp zero-click, China outs NSA securityconversations.com/episode/a…
151