Silas Cutler
@silascutler.bsky.social
You may know me from your server logs. #Malware, Hacks, Internet Scanning, #CTI
The past few months have been incredible in the malware analysis space. AI has enabled a lot of folks to rapidly catch up in this space to where top researchers were about 5 years ago. The pace has wildly increased, but what I'm seeing set the leaders in this space is depth.
New Shitty Kitty V2 inventory available for pickup at #defcon34 at uberflux.com/product/UF-SK2 @defcon.bsky.social #defcon #badgelife
Registration and CFP for 🆘VOLUME II is officially OPEN! On October 22, 2026, we return to Brussels to showcase a day of community and discussions on the latest developments in state-sponsored operations and the actors & institutions that champion them.
Harness, Scaffold, and the AI Agent Terms Worth Getting Right https://huggingface.co/blog/agent-glossary
Start your weekend off right by watching the amazing @arianamirian.bsky.social talk about the way those gross text scams work and how she's working to disrupt their whole situation. youtu.be/5ArUiAjBoB8?...
Defeating Online Scams and Disrupting the Cybercrime Chain | Ariana Mirian
YouTube video by Decipher
youtu.be
Five years ago today Philip Reiner, Michael Daniel, John Davis, Jen Ellis Christopher Painter, Michael Phillips, Kemba Walden and I, together with the then tiny but mighty IST team and the essential input of the 60 plus Task Force participants, launched the #RansomwareTaskForce Report.
In the 5 years since the launch of the #RansomwareTaskForce, #ransomware has become a well-known threat with devastating consequences. On 4/30, Anja Shortland sits down with the RTF Co-chairs to reflect on progress & celebrate the release of her new book, Dark Screens! 🛡️ Register: bit.ly/4vNxe8S
Countdown is real ⌛️ Next week‼️ #ThreatResearch community gathers in Málaga 🇪🇸 Time to remind our PIVOTcon song: soundcloud.com/argonix/pivo... But watch out — it's a banger! #CTI #ThreatIntel #PIVOTcon26
a man in a white sweater is playing a keyboard with a vase of flowers in the background
ALT: a man in a white sweater is playing a keyboard with a vase of flowers in the background
media.tenor.com
LABScon 2026 Call for Papers is open. Sept 16–19, Scottsdale. Invite-only. Fifth year.
LABScon - Security Research in Real Time | LABScon
Join us September 16-19th for LABScon, an intimate, invite-only event for the top cybersecurity minds to gather, share cutting-edge research.
labscon.io
Bay Area hackers GO SEE THIS MOVIE. Trust your boy. It’s great!
Bay Area friends! JOYBUBBLES is coming for SFFILM's San Francisco International Film Festival! Screening on April 25 at 3:30 PM. Director Rachael J Morrison, producers Sarah Winshall, Will Butler, and Annie Marr will be in attendance for a post-screening Q&A. ☎️ Get tickets NOW — loom.ly/pz47E20
One of the best pieces I’ve seen on the omnishambles of the FTC, by @masnick.com www.techdirt.com/2026/04/16/o...
Oh Look, The MAGA FTC Built The Censorship Industrial Complex It Was Screaming About
We’ve been covering the Trump administration’s escalating campaign against NewsGuard for a while now. It started with the House Oversight Committee’s absurd investigation of the c…
techdirt.com
I've been uploading #hacking magazines from #China, some of which have been removed for reasons I don't understand, to Internet Archive. This is a decent scan of an issue of Hacker Defence (or Hacker Defence Line?) from I think the early to mid 00s. #hacker #history archive.org/details/hack...
Hacker Defence (黑客防线) : 黑客防线 : Free Download, Borrow, and Streaming : Internet Archive
Cannot work out the date associated with this issue but judging by the content it is probably early 00s.Hacker Line is the only Internet and computer...
archive.org
NEW: The U.S. Treasury is sanctioning a Russian zero-day broker called Operation Zero. U.S. officials confirmed that Operation Zero was the company that bought exploits stolen by the former boss of U.S. defense contractor L3Harris Trenchant. Trenchant made hacking tools for the U.S. and its allies.
Treasury sanctions Russian zero-day broker accused of buying exploits stolen from U.S. defense contractor | TechCrunch
The U.S. Treasury announced it was imposing sanctions against a Russian broker of zero-day exploits, its founder and two affiliates, citing a threat to U.S. national security. Another affiliated zero-...
techcrunch.com
Our blog at @Censys now has a proper RSS feed https://censys.com/feed/ (cc: @Feedly #GoogleReader)
I've been seeing Vshell in #opendirs for a few years. With the recent attention, it was time to do a proper write-up on it: https://censys.com/blog/vshell/
Check out the agenda for [un]prompted . It was incredible to see what folks submitted and I'm excited to see everyone in March https://unpromptedcon.org/
🔥 👀 New research from @morecoffeeplz.bsky.social and @silascutler.bsky.social on the "silent" AI network, a massive, unmanaged layer of open-source AI infrastructure operating in the shadows.
🧵 175,000+ exposed AI hosts. Zero guardrails. New research from @sentinellabs.bsky.social and @censys.bsky.social reveals a massive, unmanaged layer of open-source AI infrastructure operating in the shadows. s1.ai/si-llama Here is what you need to know about the "silent" AI network. ⤵️
New research from @silascutler.bsky.social and myself. We tracked 175k exposed Ollama endpoints for nearly a year. Collected and analyzed custom models, sizes, quantizations, system prompts, and more.
🔥 👀 New research from @morecoffeeplz.bsky.social and @silascutler.bsky.social on the "silent" AI network, a massive, unmanaged layer of open-source AI infrastructure operating in the shadows.
How do you track DDoS infrastructure when C2 servers rarely last a day? @vtx-savage.bsky.social and @silascutler.bsky.social are breaking down real-world DDoSia hunting using the Synapse-Censys Power-Up in our next webinar. vertex.link/events/censy...
Join me next week at the @SANSInstitute #CTISummit in Arlington, VA where I'll be presenting on an operation against the infostealer #Rhadamanthys from early in its development. Register @ https://www.sans.org/u/1CtB
We're hosting a webinar with @censys.bsky.social! Attackers can rotate infrastructure faster than threat hunters can keep up. Learn how defenders can pivot from indicators to infrastructure-centric intelligence. @vtx-savage.bsky.social + @silascutler.bsky.social vertex.link/events/censy...
Come see me talk at the @SANSInstitute #CTISummit in Arlington, VA about the infostealer #Rhadamanthys during its early development. https://www.sans.org/u/1CtB
Critical MongoDB Uninitialized Memory Disclosure Vulnerability [CVE-2025-14847] #MongoBleed From Censys scanning, we're seeing around 87,000 possibly vulnerable hosts https://censys.com/advisory/cve-2025-14847
🚨🚨🚨 PATCH YO' MONGODB - PUBLIC POC AVAILABLE 🚨🚨🚨 m.cje.io/4q2Bi1Y
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
m.cje.io
ColdFusion++ Christmas Campaign: Catching a Coordinated Callback Calamity https://www.labs.greynoise.io/grimoire/2025-12-26-coldfusion/