Silas Cutler

Silas Cutler

@silascutler.bsky.social

You may know me from your server logs. #Malware, Hacks, Internet Scanning, #CTI

5,014 Followers 511 Following 142 Posts Joined May 2023
2 weeks ago
Preview
Treasury sanctions Russian zero-day broker accused of buying exploits stolen from U.S. defense contractor | TechCrunch The U.S. Treasury announced it was imposing sanctions against a Russian broker of zero-day exploits, its founder and two affiliates, citing a threat to U.S. national security. Another affiliated zero-...

NEW: The U.S. Treasury is sanctioning a Russian zero-day broker called Operation Zero. U.S. officials confirmed that Operation Zero was the company that bought exploits stolen by the former boss of U.S. defense contractor L3Harris Trenchant.

Trenchant made hacking tools for the U.S. and its allies.

5 4 0 1
2 weeks ago

Our blog at @Censys now has a proper RSS feed https://censys.com/feed/
(cc: @Feedly #GoogleReader)

8 3 1 0
2 weeks ago
CensysVshell: A Chinese-Language Alternative to Cobalt StrikeΒ Odyssey Stealer: Inside a macOS Crypto-Stealing OperationMalicious Notepad++ Network InfrastructurePrioritize What Matters: Introducing Cloud Asset Context in Censys ASMHiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP InfrastructureVoicemail Trap: German-Language Voicemail Lure Leads to Remote AccessOpenClaw in the Wild: Mapping the Public Exposure of a Viral AI AssistantAsyncRAT C2 Activity at Internet ScaleCensys Recognized as One of the Most Popular New Integrations in the Wiz Integration Network (WIN) Partner IndexA Tiny Peek Into Unauthenticated SOCKS Proxies

I'm so excited to finally be able to send this to you: censys.com/feed/

4 0 0 1
2 weeks ago

I've been seeing Vshell in #opendirs for a few years. With the recent attention, it was time to do a proper write-up on it:
https://censys.com/blog/vshell/

3 1 0 0
3 weeks ago
Post image

Check out the agenda for [un]prompted . It was incredible to see what folks submitted and I'm excited to see everyone in March

https://unpromptedcon.org/

4 2 1 1
3 weeks ago
Post image

#InternetOfPlants

6 0 0 0
1 month ago
Post image
1 0 1 0
1 month ago

πŸ”₯ πŸ‘€ New research from @morecoffeeplz.bsky.social
and @silascutler.bsky.social on the "silent" AI network, a massive, unmanaged layer of open-source AI infrastructure operating in the shadows.

4 1 1 1
1 month ago

New research from @silascutler.bsky.social and myself.

We tracked 175k exposed Ollama endpoints for nearly a year. Collected and analyzed custom models, sizes, quantizations, system prompts, and more.

3 1 1 0
1 month ago
Video thumbnail

How do you track DDoS infrastructure when C2 servers rarely last a day?

@vtx-savage.bsky.social and @silascutler.bsky.social are breaking down real-world DDoSia hunting using the Synapse-Censys Power-Up in our next webinar.
vertex.link/events/censy...

5 4 0 0
1 month ago
Post image

Join me next week at the @SANSInstitute #CTISummit in Arlington, VA where I'll be presenting on an operation against the infostealer #Rhadamanthys from early in its development.

Register @ https://www.sans.org/u/1CtB

2 1 0 0
2 months ago
Post image

We're hosting a webinar with @censys.bsky.social! Attackers can rotate infrastructure faster than threat hunters can keep up. Learn how defenders can pivot from indicators to infrastructure-centric intelligence.

@vtx-savage.bsky.social + @silascutler.bsky.social

vertex.link/events/censy...

5 3 0 2
2 months ago
Post image

Come see me talk at the @SANSInstitute #CTISummit in Arlington, VA about the infostealer #Rhadamanthys during its early development.

https://www.sans.org/u/1CtB

6 1 0 0
2 months ago

What a quote.

3,163 900 13 17
2 months ago
Post image

Critical MongoDB Uninitialized Memory Disclosure Vulnerability [CVE-2025-14847] #MongoBleed

From Censys scanning, we're seeing around 87,000 possibly vulnerable hosts

https://censys.com/advisory/cve-2025-14847

1 0 0 0
2 months ago
Preview
Merry Christmas Day! Have a MongoDB security incident. Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.

🚨🚨🚨 PATCH YO' MONGODB - PUBLIC POC AVAILABLE 🚨🚨🚨

m.cje.io/4q2Bi1Y

4 2 1 0
2 months ago

ColdFusion++ Christmas Campaign: Catching a Coordinated Callback Calamity

https://www.labs.greynoise.io/grimoire/2025-12-26-coldfusion/

4 3 0 0
2 months ago
Post image Post image

Some unusual #CobaltStrike activity we observed at Censys before the holiday. At the start of December, we saw a spike in CobaltStrike in AS138415 followed by a matching spike two days after on AS133199.

Report: https://censys.com/blog/recap-of-a-suspicious-surge-in-cobalt-strike

4 1 0 1
2 months ago
Post image

I'm speaking at the @SANSInstitute #CTISummit on an operation against #Rhadamanthys years before #OperationEndgame.

https://www.sans.org/u/1CtB

9 2 0 0
2 months ago

Dave Stern is an unrecognized national hero.

11 0 1 0
2 months ago
Post image

Scoop: The lone employee behind CISA's Pre-Ransomware Notification Initiative resigned on Friday rather than take a forced reassignment to FEMA.

CISA says PRNI will continue, but sources said David Stern's loss will be a major setback for it.

My story: www.cybersecuritydive.com/news/cisa-ra...

257 132 7 16
2 months ago
Video thumbnail

I’m old enough to remember when CBS News would never have surrendered to a demagogic president or any other politician. Remember Edward R. Murrow?

12,907 4,495 581 226
2 months ago
Post image Post image Post image

For anyone looking to optimize their news feeds, I've been using Miniflux (https://miniflux.app/) as an RSS reader for the past few years.

Recently I found it also works well for tracking newly released mechanical keyboards.

5 0 0 0
2 months ago
Post image

#DistillingCyber podcast is back with a special episode featuring Stacy O'Mara & Leonard Bailey.

Tune in to explore whether offensive cyber operations should be used to counter cyber threats β€” if so, who should be authorized to carry them out? www.centerforcybersecuritypolicy.org/insights-and...

2 2 0 0
2 months ago
Post image

https://unpromptedcon.org/

Con: 3-4 March 2026
CFP closes 28 January 2026, Submit at https://sessionize.com/unprompted-the-ai-security-practitio/

1 0 0 0
2 months ago
Post image

NoName057(16) are still active despite last week's DOJ indictment. We looked into how their DDoSia platform works:
https://censys.com/blog/ddosia-infrastructure

1 0 0 0
3 months ago
Post image

I'm sorry if I'm behind on replying to email. I'm at this point for reference

8 0 0 0
3 months ago

New threat, Kazu ransomware. @ecrime.ch has new information on this threat actor. Kazu has claimed ~35 mostly public sector victims across Latin America, the Middle East, and Asia. πŸ‘€ cc @gate15.bsky.social @ransomwaresommelier.com @silascutler.bsky.social #cybersecurity #ransomware

2 3 0 0
4 months ago

Part 2 of @DomainTools research is out: Inside the Great Firewall Part 2: Technical Infrastructure

https://dti.domaintools.com/inside-the-great-firewall-part-2-technical-infrastructure/

4 1 0 0
4 months ago
Post image

Interested in Jump The Wall? Applications close Nov 7 πŸ”₯
www.districtcon.org/jtw

3 4 0 0