Silas Cutler's Avatar

Silas Cutler

@silascutler.bsky.social

You may know me from your server logs. #Malware, Hacks, Internet Scanning, #CTI

5,013 Followers  |  511 Following  |  142 Posts  |  Joined: 01.05.2023
Posts Following

Posts by Silas Cutler (@silascutler.bsky.social)

Preview
Treasury sanctions Russian zero-day broker accused of buying exploits stolen from U.S. defense contractor | TechCrunch The U.S. Treasury announced it was imposing sanctions against a Russian broker of zero-day exploits, its founder and two affiliates, citing a threat to U.S. national security. Another affiliated zero-...

NEW: The U.S. Treasury is sanctioning a Russian zero-day broker called Operation Zero. U.S. officials confirmed that Operation Zero was the company that bought exploits stolen by the former boss of U.S. defense contractor L3Harris Trenchant.

Trenchant made hacking tools for the U.S. and its allies.

24.02.2026 19:05 β€” πŸ‘ 5    πŸ” 4    πŸ’¬ 0    πŸ“Œ 1

Our blog at @Censys now has a proper RSS feed https://censys.com/feed/
(cc: @Feedly #GoogleReader)

24.02.2026 16:00 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0
CensysVshell: A Chinese-Language Alternative to Cobalt StrikeΒ Odyssey Stealer: Inside a macOS Crypto-Stealing OperationMalicious Notepad++ Network InfrastructurePrioritize What Matters: Introducing Cloud Asset Context in Censys ASMHiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP InfrastructureVoicemail Trap: German-Language Voicemail Lure Leads to Remote AccessOpenClaw in the Wild: Mapping the Public Exposure of a Viral AI AssistantAsyncRAT C2 Activity at Internet ScaleCensys Recognized as One of the Most Popular New Integrations in the Wiz Integration Network (WIN) Partner IndexA Tiny Peek Into Unauthenticated SOCKS Proxies

I'm so excited to finally be able to send this to you: censys.com/feed/

24.02.2026 15:59 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 1

I've been seeing Vshell in #opendirs for a few years. With the recent attention, it was time to do a proper write-up on it:
https://censys.com/blog/vshell/

24.02.2026 14:50 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

Check out the agenda for [un]prompted . It was incredible to see what folks submitted and I'm excited to see everyone in March

https://unpromptedcon.org/

13.02.2026 15:00 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 1
Post image

#InternetOfPlants

12.02.2026 20:00 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image 10.02.2026 16:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

πŸ”₯ πŸ‘€ New research from @morecoffeeplz.bsky.social
and @silascutler.bsky.social on the "silent" AI network, a massive, unmanaged layer of open-source AI infrastructure operating in the shadows.

29.01.2026 16:42 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 1    πŸ“Œ 1

New research from @silascutler.bsky.social and myself.

We tracked 175k exposed Ollama endpoints for nearly a year. Collected and analyzed custom models, sizes, quantizations, system prompts, and more.

29.01.2026 20:03 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Video thumbnail

How do you track DDoS infrastructure when C2 servers rarely last a day?

@vtx-savage.bsky.social and @silascutler.bsky.social are breaking down real-world DDoSia hunting using the Synapse-Censys Power-Up in our next webinar.
vertex.link/events/censy...

21.01.2026 15:30 β€” πŸ‘ 5    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Post image

Join me next week at the @SANSInstitute #CTISummit in Arlington, VA where I'll be presenting on an operation against the infostealer #Rhadamanthys from early in its development.

Register @ https://www.sans.org/u/1CtB

20.01.2026 20:00 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

We're hosting a webinar with @censys.bsky.social! Attackers can rotate infrastructure faster than threat hunters can keep up. Learn how defenders can pivot from indicators to infrastructure-centric intelligence.

@vtx-savage.bsky.social + @silascutler.bsky.social

vertex.link/events/censy...

08.01.2026 19:04 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 2
Post image

Come see me talk at the @SANSInstitute #CTISummit in Arlington, VA about the infostealer #Rhadamanthys during its early development.

https://www.sans.org/u/1CtB

06.01.2026 16:00 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

What a quote.

29.12.2025 18:42 β€” πŸ‘ 3169    πŸ” 900    πŸ’¬ 13    πŸ“Œ 17
Post image

Critical MongoDB Uninitialized Memory Disclosure Vulnerability [CVE-2025-14847] #MongoBleed

From Censys scanning, we're seeing around 87,000 possibly vulnerable hosts

https://censys.com/advisory/cve-2025-14847

29.12.2025 18:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Merry Christmas Day! Have a MongoDB security incident. Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.

🚨🚨🚨 PATCH YO' MONGODB - PUBLIC POC AVAILABLE 🚨🚨🚨

m.cje.io/4q2Bi1Y

27.12.2025 13:39 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

ColdFusion++ Christmas Campaign: Catching a Coordinated Callback Calamity

https://www.labs.greynoise.io/grimoire/2025-12-26-coldfusion/

26.12.2025 15:51 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Some unusual #CobaltStrike activity we observed at Censys before the holiday. At the start of December, we saw a spike in CobaltStrike in AS138415 followed by a matching spike two days after on AS133199.

Report: https://censys.com/blog/recap-of-a-suspicious-surge-in-cobalt-strike

23.12.2025 19:15 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1
Post image

I'm speaking at the @SANSInstitute #CTISummit on an operation against #Rhadamanthys years before #OperationEndgame.

https://www.sans.org/u/1CtB

23.12.2025 19:00 β€” πŸ‘ 9    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Dave Stern is an unrecognized national hero.

23.12.2025 15:57 β€” πŸ‘ 11    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Scoop: The lone employee behind CISA's Pre-Ransomware Notification Initiative resigned on Friday rather than take a forced reassignment to FEMA.

CISA says PRNI will continue, but sources said David Stern's loss will be a major setback for it.

My story: www.cybersecuritydive.com/news/cisa-ra...

23.12.2025 15:50 β€” πŸ‘ 257    πŸ” 132    πŸ’¬ 7    πŸ“Œ 16
Video thumbnail

I’m old enough to remember when CBS News would never have surrendered to a demagogic president or any other politician. Remember Edward R. Murrow?

22.12.2025 18:01 β€” πŸ‘ 12911    πŸ” 4497    πŸ’¬ 581    πŸ“Œ 226
Post image Post image Post image

For anyone looking to optimize their news feeds, I've been using Miniflux (https://miniflux.app/) as an RSS reader for the past few years.

Recently I found it also works well for tracking newly released mechanical keyboards.

19.12.2025 18:54 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

#DistillingCyber podcast is back with a special episode featuring Stacy O'Mara & Leonard Bailey.

Tune in to explore whether offensive cyber operations should be used to counter cyber threats β€” if so, who should be authorized to carry them out? www.centerforcybersecuritypolicy.org/insights-and...

19.12.2025 17:22 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

https://unpromptedcon.org/

Con: 3-4 March 2026
CFP closes 28 January 2026, Submit at https://sessionize.com/unprompted-the-ai-security-practitio/

19.12.2025 15:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

NoName057(16) are still active despite last week's DOJ indictment. We looked into how their DDoSia platform works:
https://censys.com/blog/ddosia-infrastructure

16.12.2025 15:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I'm sorry if I'm behind on replying to email. I'm at this point for reference

03.12.2025 01:27 β€” πŸ‘ 8    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

New threat, Kazu ransomware. @ecrime.ch has new information on this threat actor. Kazu has claimed ~35 mostly public sector victims across Latin America, the Middle East, and Asia. πŸ‘€ cc @gate15.bsky.social @ransomwaresommelier.com @silascutler.bsky.social #cybersecurity #ransomware

12.11.2025 11:38 β€” πŸ‘ 2    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

Part 2 of @DomainTools research is out: Inside the Great Firewall Part 2: Technical Infrastructure

https://dti.domaintools.com/inside-the-great-firewall-part-2-technical-infrastructure/

06.11.2025 20:25 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Interested in Jump The Wall? Applications close Nov 7 πŸ”₯
www.districtcon.org/jtw

31.10.2025 19:52 β€” πŸ‘ 3    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0