dcuthbert Profile Banner
Daniel Cuthbert Profile
Daniel Cuthbert

@dcuthbert

Followers
32K
Following
46K
Media
3K
Statuses
16K

Documentary photographer, old creaky hacker. Co-author of @OWASP ASVS standard. Blackhat/Brucon Review Board & Co_chair UK Gov Cyber Security Advisory Board

Airport lounges.
Joined April 2008
Don't wanna be here? Send us removal request.
@dcuthbert
Daniel Cuthbert
58 minutes
When VX brings receipts…
@vxunderground
vx-underground
3 hours
@isabellasg3 @SamouraiWallet Isa, we don't know each other, and you're a person behind this computer, so I don't want to sound rude. Did you actually read the court documents? That's a serious question. I'm asking because, based on what you've said, it sounds like you have NOT read the court documents. The
0
0
0
@dcuthbert
Daniel Cuthbert
4 hours
Forest, MTB’ing and possibly the hardest camera ever made. The mighty Nikon F5. Saw action inside Myanmar with the Karen Rebels, Pripyat (Chernobyl), and now on dad duty Such an amazing bit of kit this
1
0
4
@dcuthbert
Daniel Cuthbert
4 hours
Instagram has some truly amazing human beings. Like Taco El Flako https://t.co/xfV5FmXUQL NGL, the style is inspiring and I am indeed wanting a car and pants.
0
0
0
@dcuthbert
Daniel Cuthbert
1 day
2026: here’s to less touch screen wank and more buttons. More tactile knobs. More of “I can feel it” https://t.co/8bWOInKdZs
Tweet card summary image
instagram.com
0
1
6
@OliviaGalluccii
Olivia Gallucci ✨
2 days
I'm thrilled to share my latest post: Why Packers are Rare and Sus on macOS! 📦 I discuss how macOS's native security mechanisms make traditional packing techniques uncommon, and why third-party packers are often a bad fit for Mac devs and offensive security engineers.
0
8
53
@dcuthbert
Daniel Cuthbert
4 days
There is just something so compelling, so 'grab you by the neck and make you look...' about large format photography. Bob Thall's work from the 70s and 80s is incredible on so many levels. Maybe it's the depth and scale, or the cars, it just resonates https://t.co/et6Goh3nbN
0
0
10
@dcuthbert
Daniel Cuthbert
4 days
Saturdays....
1
1
16
@dcuthbert
Daniel Cuthbert
5 days
When @halvarflake writes, i stop and read. Ask your LLM for receipts: What I learned teaching Claude C++ crash triage https://t.co/AiBGSIa92i
1
20
80
@dcuthbert
Daniel Cuthbert
5 days
Good week for RAPTOR, and thanks the community for all the PR's and patches. Like https://t.co/phktr8fmw7 who added an offsec-specialist skillset We are also working hard on the crash analysis capabilites
1
7
46
@dcuthbert
Daniel Cuthbert
5 days
Hell, even SAML says this https://t.co/zctBYGbTT3 Yes, I'm totes fun at parties but I'm sick of how lazy SF tech companies are with security and standards. Lazy ass shits, the lot of them
0
0
0
@dcuthbert
Daniel Cuthbert
5 days
Rules aside, it's also a shit idea. https://t.co/04yA2jvpnM Client-side redirects can be manipulated if the redirect URL is exposed in the page content, they're harder to audit and validate programmatically and tools and proxies can't properly follow/validate the chain
1
0
0
@dcuthbert
Daniel Cuthbert
5 days
Section 6.4 defines redirect status codes (301, 302, 303, 307, 308) specifically for this purpose. Using a 200 OK with JavaScript to redirect circumvents the intended HTTP semantics for redirection.
1
0
0
@dcuthbert
Daniel Cuthbert
5 days
Waht in the shittery names of jack and sally... Using a client-side redirect via satans spawn (java lite, or javascript) instead of a proper server-side HTTP 302/303 redirect. Rules, we need dem rules https://t.co/9sPoa1IAup
datatracker.ietf.org
The Hypertext Transfer Protocol (HTTP) is a stateless \%application- level protocol for distributed, collaborative, hypertext information systems. This document defines the semantics of HTTP/1.1...
1
0
0
@dcuthbert
Daniel Cuthbert
5 days
The more I dig into auth and identity, the more I rage at how so many SaaS companies abuse standards. Lets take the humble redirect where we utilise a secondary IdP
1
0
1
@dcuthbert
Daniel Cuthbert
6 days
Finally an iPhone was found communicating data, without their permission, to a nation state IP from a country that the other country doesn’t like Yes the BH network is hostile but the NOC teams are all over this like hawks
0
0
2
@dcuthbert
Daniel Cuthbert
6 days
In a react world, whoever wrote this malware to use this, well ok 9/10
0
0
3
@dcuthbert
Daniel Cuthbert
6 days
So what annoys Bart? Well Jon… Translation apps with no crypto File syncs in the clear And endpoint protection platform that leak endpoint info and user accounts via HTTP
0
0
1
@dcuthbert
Daniel Cuthbert
6 days
Always love the @BlackHatEvents NOC session. The stuff they detect, remediate and destroy (bad) is something else
3
0
6
@dcuthbert
Daniel Cuthbert
6 days
Singapore’s Ministry of Home Affairs was speaking about UNC3886. They didn’t name china specifically, but did name and shame to some degree but from a cultural standpoint, this is about as far as they go
0
0
2
@dcuthbert
Daniel Cuthbert
6 days
Operation Futile report was a significant shift of “he said, she said” https://t.co/LgTwP6gYTy Very technical
0
0
1