From a zero-day vulnerability discovered in Google Chrome to a zero-click flaw enabling the installation of spyware on iOS devices, self-professed “creaky old hacker” Daniel Cuthbert is undoubtedly right: It’s been “really bad” regarding bugs in vendor products within recent weeks.
“The problem is, bugs like these are being leveraged by a big, global complex to access data — and it has meant that technology has now allowed us to spy on anybody,” he explained during his Scot-Secure West keynote at Strathclyde University’s Technology and Innovation Centre on 14 September.
On matters of bugs, exploitations, and cybersecurity, Cuthbert is a thoroughly authoritative figure: He serves as Santander’s Global Head of Cybersecurity Research, and sits on multiple UK Government cyber advisory boards. And if his name looks familiar, that might be due to headlines in the press: In 2005, at age 28, he was convicted of breaking Section 1 of the Computer Misuse Act 1990.
Witnessing first-hand how, since the 1990s, the exploitation of bugs has undergone a metamorphosis into something undeniably sinister on myriad fronts — and providing insight into that evolution — was the focal point of Cuthbert’s engaging yet sobering keynote.
For those who didn’t get the chance to hear him speak in person, here’s a rundown of Cuthbert’s talk. It makes for rather apt reading, considering we’re living through “a golden age of espionage in terms of stealing information” — a phrase Cuthbert referenced that was formulated by Kenneth Geers, an ex-intelligence expert and personal friend of his.
Hello, World
Cuthbert’s own interest in bugs began during the early days of the Internet. He started hacking around 1994, and without any followable how-to guides or explainers. “We learned, we built exploits using Perl, we shared those exploits with friends, and we broke into stuff,” he explained.
While both individuals and the motley crew hacking groups that formed “were scanning and finding stuff,” it was also the case that “people weren’t really using the Internet,” meaning that it was something of a niche technological sport — and while some damage was possible, it wasn’t close to the scale of havoc seen today.
As the 1990s progressed, the scene experienced some ramping up, as did the accessibility of bug exploitation. As Cuthbert noted, ~el8 — the anti-security hacktivist collective — had “called out the fact that Bugtraq, an early mailing list, was facilitating an industry and a consortium of ‘script kiddies.’ Now, the term ‘script kiddies’ came about from around that time, where we saw people taking proof of concept exploit code that was shared on Bugtraq, and just using it willy-nilly to do stuff on the Internet.”
Cuthbert acknowledged this observation was true: “They were right — what we were doing was arming a bunch of people that were doing damage.” Though, Cuthbert mentioned that it still, in the grand scheme of things, “never really kicked off, because it was the early days.”
For Cuthbert, the turning point came with the new millennium, and with a vulnerability logged in the recently-created Common Vulnerabilities and Exposures database as CVE-2002-0392.
He relayed that “2002 was an interesting time — CVEs were just out — and this was the Apache scalp vulnerability, the exploit that I wrote. What was interesting about this was the threat intelligence experts at the time deemed that the vulnerability was not exploitable.”
This then “caused a massive stir with three amazing friends who are called GOBBLES. GOBBLES had enough and they said, ‘Do you know what? Screw you all, we’re going to write a multi-staged, multi-payload exploit’ that effectively wreaked a lot of havoc on the Internet at the time, because there was no patch from Apache.”
It was this that “started to set the scenes as to the way the world of the sinister bug was changing,” noted Cuthbert.
The War on Bugs
On New Year’s Eve 2004, just days after the Indian Ocean earthquake and tsunami disaster, Cuthbert donated to a website that was collecting money to support those affected. However, after making the payment and not being directed to a confirmation or thank-you page, he grew suspicious; could he have been duped by a phishing site?
In response, he decided to investigate the site’s security — which involved hacking it — and activated an alert for the website’s intruder detection system. This consequently led to his arrest and eventual conviction, in which he was charged £400 for the “offence” and £600 in further costs.
Off the back of his arrest and conviction, Cuthbert moved to Bangkok, Thailand, following in the footsteps of many other hackers at the time. Most notably, he lived with a South African hacker known as “the Grucq” — and it was the way in which the Grucq was working with both hackers and governments that was especially interesting, if not pivotal.
“Everyone knew the Grucq, and the Grucq knew all the exploit writers who now saw that giving away exploits for free was a really stupid business idea, because at the time you could get £200-250K and more, no questions asked, for certain zero-days,” Cuthbert explained.
“So, the Grucq acted as the middleman to move money around from governments who were buying exploits but didn’t want to gain access to the people that were selling the exploits, because it was a weird anomaly.”
After some media attention, the practice — the Grucq wasn’t alone in doing it — was pushed further underground. Then, as Cuthbert stated, “what happened after that was a really, really ugly stage: We started to see a big rise in the global surveillance industry.”
Technological Omnipresence
“Surveillance and interception is nothing new,” Cuthbert made clear. “Julius Caesar put together a great group of people to do surveillance.”
Over the centuries, the methodologies have adapted both to and alongside technological innovation: “If you look at the history of surveillance, it’s moved from the interception of letters, messages, and so on, to the interception of telephone calls, then we started to move into computers, and then into the mobile world — and now we have geolocation.”
“This industry thrives on bugs; it needs bugs and these vulnerabilities in the products that we all use,” he said. The bugs are then “being leveraged by a big, global complex to access data — and it has meant that technology has now allowed us to spy on anybody.”
To elucidate, Cuthbert posed a rhetorical question to the audience: “How many of you are aware that the ad tracking network is far more pervasive and powerful than any of my friends at the NSA, CIA, or GCHQ? It’s a phenomenally powerful industry that exploits bugs and keeps track of you. In fact, now, if I want to learn anything about you, I go to a data broker, and I buy data from your mobile phone, and I buy data from the apps that are exploiting bugs and how mobile operating systems work.”
This is but part of the infrastructure making up our contemporary digital panopticon. As Cuthbert explained: “In the late 1700s, Jeremy Bentham came up with the panopticon. The panopticon is the ideal jail, where all the cells are open, you have a single place in the middle where a guardsperson can look at all the people, and there’s no such thing as privacy. The panopticon is where we’re at.”
To further highlight our digital panopticon’s ubiquity, Cuthbert touched on lawful intercept tools, which facilitate electronic surveillance by law enforcement agencies. “Four years ago, I started to look at how big the lawful intercept world was; this world that capitalises on bugs, bugs in vendor products, bugs in software — bugs in everything.”
After helping build out a tool called Maltego, Cuthbert used it to “map out the global surveillance network” — which he did. He subsequently found “a lot of companies, a lot of capabilities, a lot of countries, all selling some form of exploitation of a bug,” with around 120 companies specifically offering lawful intercept across the planet.
This indeed, and as referenced at the beginning of the captivating keynote, is a golden age of espionage in terms of stealing information.
Recommended reading
- MI6 Is Using AI to Augment the Secret Work of Its Human Spies
- New MI5 Organisation to Combat State-backed Security Threats
- NCSC Helps Discover Russian-Espionage ‘Snake’ Tool in over 50 Countries
Nefarious Baddies
“It’s hard to talk about the bug world without talking about the baddies in the room,” stated Cuthbert, despite just discussing lawful intercept and the ad tracking network — highlighting how nefarious the “baddies” are in actuality.
While many sinister incidents and anecdotes could’ve been referenced, he relayed one particular story at the intersection of Mexican politics, the sugar industry, and bugs.
In the mid-2010s, “Mexico realised that it had a real big problem with obesity, and that sugar was everywhere,” explained Cuthbert. “So they set together a task force to eradicate sugar from the Mexican diet. But there were certain people in the sugar industry who didn’t like that.”
In response, phishing messages and links were sent to government employees and campaigners at the forefront of advocating for Mexico’s soda tax, with the links containing invasive spyware originally developed by an infamous cyber arms dealer.
The phishing messages themselves concerned the hoaxed sudden deaths of the target’s family members, as well as marital affairs — ushering the targets to click the links out of fear and instinct. Ultimately, as Cuthbert noted, the adversaries “made use of the dealer’s capability to send exploits on to the people involved in changing the law.”
As a more recent example of exploitation for nefarious political reasons, Cuthbert referenced an FBI report relating to how “North Korea stole around 40 million from another Web3 wallet,” stipulating that “the entire complex of North Korea earning money with bugs is pretty phenomenal.”
These stories are just two instances of how we have “big players messing around with politics and bugs” — and are but two the general public are privy to; perhaps the very tip of the gargantuan, mostly submerged iceberg.
Secure by Design
As Cuthbert’s talk began winding down, he noted the onus on vendors shipping and selling products to ensure that their offerings are, in terms of security, watertight. After all, it’s the proliferation of bugs that are continually feeding this modern-day beast.
“If we start to look at how prolific bugs are in our industry, we start to look at things like CISA’s KEV, and CISA’s KEV for me is our mirror of the industry,” underscored Cuthbert. The U.S. Cybersecurity & Infrastructure Agency’s Known Exploited Vulnerabilities (KEV) Catalog is, as its name suggests, a directory of discovered bugs that’ve been exploited in the wild — but it also functions as a dishonourable list of vendors.
“What’s amazing is what Jen Easterly and the team are doing at CISA, saying, ‘Right, we need to get vendors to do more. We’re going to shame vendors and put their name on a government website to say your code, applications, and products are being exploited — fix it,’” he described.
However, in doing so, KEV has highlighted the sheer number of bugs that are being exploited and leveraged for dubious means. “I checked the other day and we’re about to hit 1,000 products listed in KEV. So, something’s not working, we’re finding more and more bugs every day, and more and more vendors are getting hit.”
As somebody who sits on UK Government advisory boards, Cuthbert mentioned his relief that Secure by Design — a piece of legislation requiring IoT product manufacturers to comply with new baseline security standards — is coming into effect here in spring 2024.
“I can’t believe I’m standing here as a hacker, as a miscreant, saying we do need some kind of regulation. The reality is we need the threat of regulation: We need people to know that you can no longer sell and ship products that are knowingly insecure. We wouldn’t expect it with a car, we wouldn’t expect it with the seat that you’re sitting on. Why do we willingly let vendors ship products that are woefully insecure, but charge a large amount of money? This is where Secure by Design comes in.”
Regulation — and/or the threat of it — is just one of the initiatives to help drive down the proliferation of bugs however, because it goes past governments and involves the global technology industry as a whole.
In light of this, Cuthbert advocated for the international tech industry, starting with the attendees at Scot-Secure West, to “be more aggressive and ask more questions of the people we’re buying kit from.”
“What we need to do now is we need to start going up to vendors and asking them, ‘What are you actually doing to make your product secure — not to make us secure — but make your product secure?,’” he suggested.
Cuthbert’s actionable advice here can be thought of as a form of community action, or a kind of collective bargaining; a united step towards driving down the very thing that has captured his curiosity and thoughts for nigh on decades: bug exploitation.
Perhaps, by doing so, we can help usher in a more beneficial golden age than the one we’re currently withstanding.





