Daniel Cuthbert

3K Followers
236 Following
426 Posts
Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

Best damn hacking video in decades and it's my dude, Mr @joegrand

https://www.youtube.com/watch?v=MhJoJRqJ0Wc

$75,000,000 Crypto Wallet Bulk Hack

YouTube

We've been testing a pretty sweet new feat for RAPTOR with the exploitability validation pipeline, which sits between vulnerability discovery & exploit generation.

Before, we be like:

scan → analyse → exploit

now, we is:

scan → validate exploitability → analyse → exploit

Typical flow now becomes:

1. Static or dynamic analysis identifies candidate vulnerabilities
2. Exploitability validation stage runs
3. Only validated findings proceed to exploit generation
4. Exploit proof of concept or patch generation follows

For us on the team, this is significant because it:

1. Reduces false positives that lead to meaningless exploit generation and token wastage (gotta be cost aware)
2. Forces the agent to reason about realistic attacker capabilities
3. Enables prioritisation based on real impact

RAPTOR now standardises human readable exploitability statuses, namely:

Exploitable
Confirmed
Proven
Disproven
Ruled Out

It's a big step forward and hopefully gives all insight into what we are working on moving forward.

Remember kids, Gobbles were amazing. Love you all

https://github.com/gadievron/raptor

When bugs actually cost lives. Great bit of research by CheckPoint on how cyber and trad war intersect

https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/

Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East - Check Point Research

Key Findings Introduction As highlighted in the Cyber Security Report 2026, cyber operations have increasingly become an additional tool in interstate conflicts, used both to support military operations and to enable ongoing battle damage assessment (BDA). During the 12-day conflict between Israel and Iran in June 2025, the compromise of cameras was likely used to support […]

Check Point Research
@cynicalsecurity @RoganDawes it truly is one of the cars that have completely bamboozled me. It has so many Italian quirks, but it is guaranteed to bring a smile to your face every time you turn the ignition on
You know when you wife is a keeper when she sends you love notes like

Totes not a fan of digital watches, but the SQFMI Watchy kinda appealed to me in a hacker/tinkererer sense.

https://watchy.sqfmi.com/

It had been 5 years since I made my first watch face, so this weekend me the the kids made a new one for 2026, Bauhaus inspired

Kids actually enjoyed working out where to put the boxes, compiling the firmware and pushing it to the watch and seeing what worked and what didnt.

Based off an esp32 and with PlatformIO helping, this is a good fun exercise for kids I feel (and adults too)

https://github.com/danielcuthbert/watchy-marina

@Viss sadly it was downhill in UX world after that.
@Viss rasterman was epic. I enjoyed hacking on e16 back in the day with a large uk Linux crew. Such an amazing window experience

So now that vibe coding has gripped the world, who’s going to be first to create the app, or apps, that start helping people block Automated Content Recognition (ACR) from working?

https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-major-win-stopping-samsung-using-its-smart-tvs-illegally-spy

Not that we need another set of firewalls, but it’s kinda clear we need something to understand when such tech is tracking you

Attorney General Ken Paxton Secures Major Win by Stopping Samsung from Using its Smart TVs to Illegally Spy on Texans

Attorney General Ken Paxton secured a major victory against Samsung, halting the company’s use of technology that allowed it to spy on Texans in their own homes.

Texas Attorney General
@reijomancer Yeah I've ordered some more as a backup like you said, got slightly concerned given the pain it is to try and reset all the accounts