Sign in

Dominic White

@singe.bsky.social
1.2K followers 770 following 681 posts

Hacker at Orange Cyberdefense's SensePost Team hello.singe.za.net

PostsRepliesMedia
Dominic White @singe.bsky.social · 29/09/2026
Agent swarms, sandboxes, and bad alignment - I had a lot of fun making sense of the current state of things with CheckPoint's AI security head Adam Ely and @techcentral.co.za's @fanievanrooyen.bsky.social in this podcast. techcentral.co.za/tcs-rogue-ai...
techcentral.co.za
TCS | Dominic White and Adam Ely on AI agents going rogue
Orange Cyberdefense’s Dominic White and Check Point’s Adam Ely discuss rogue AI agents, OpenAI’s Hugging Face breach and who is accountable.
031
Reposted by Dominic White
💥 leonjza @leonjza.bsky.social · 14/09/2026
New gowitness, 3.20! github.com/sensepost/go...
021
Dominic White @singe.bsky.social · 11/09/2026
I added post-quantum authentication (ML-DSA) checks to QuantumHello, thanks to the ML-DSA support in go 1.27 from @filippo.abyssdomain.expert and others. quantumhello.xyz
quantumhello.xyz
QuantumHello
Check whether a site supports post-quantum encryption.
032
Reposted by Dominic White
Bluesky Safety @safety.bsky.app · 02/09/2026
Dogpiling or harassing users is unacceptable. We have taken recent action against accounts for this behavior, and we will be increasing our efforts, consistent with our Community Guidelines.
bsky.social
Community Guidelines - Bluesky
8693116547
Reposted by Dominic White
Brad Fitzpatrick @bradfitz.com · 26/08/2026
I can finally talk about this, 3 years later... github.com/tailscale/ta... It's a library + CLI tool that's like netcat, but over Tailscale's data plane without any control plane (no accounts, no dependence on Tailscale the company, all open source) WireGuard + NAT traversal without IP addresses.
github.com
GitHub - tailscale/tailcat: like netcat, but over Tailscale's data plane, without Tailscale's control plane
like netcat, but over Tailscale's data plane, without Tailscale's control plane - tailscale/tailcat
823836
Dominic White @singe.bsky.social · 21/08/2026
There’s this WiFi tool I always wanted to build. But it required a massive amount of frame and code analysis. It doesn’t require much intelligence just a big ol’ mapping. But now I can get a clanker to do it. It’s nearly ready. I’m excited for this to exist in the world.
050
Dominic White @singe.bsky.social · 18/08/2026
I love @RoganDawes@infosec.exchange’s Apostille for cloning x509 certificate chains to make certs look identical to users when they're forced to eyeball them when a rogue AP presents a different cert. But I wanted something more portable with fewer deps. You can grab GOpostille 👇
A screenshot of the usage text with figlet ascii art of the name
132
Dominic White @singe.bsky.social · 18/08/2026
Over the years I’ve developed a model of vuln research where success is a function of audacity, time and follow through. You’ll notice skill wasn’t really in there - because time can beat skill and skill can reduce time but it isn’t necessary. Now AI can reduce the time - but 1/2
140
Reposted by Dominic White
Jennifer Granick @granick.bsky.social · 15/08/2026
Hi! I don't think so because generally you have to intentionally cause damage or intend to access the computer. And for civil cases "no action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware."
283
Dominic White @singe.bsky.social · 05/08/2026
Looks like the new deauth’er works on the BlackHat WPA3 network. Thanks for letting @shifttymike.bsky.social test it @darkmatter.bsky.social!
041
Reposted by Dominic White
Dominic White @singe.bsky.social · 05/08/2026
 The work from Mathy and friends showed that malicious channel switch announcements are a pretty good deauth primitive for management frame protection networks, so I added it to aircrack-ng: github.com/aircrack-ng/aircrack-ng/…
A screenshot of the new CSA deauth tool running, showing a wpa_supplicant with management frame protection connected to a hostapd with management frame protection getting deauthed. The handshake is captured in shifttymike’s new airodump-ng TUI at the bottom.
022
Dominic White @singe.bsky.social · 05/08/2026
 The work from Mathy and friends showed that malicious channel switch announcements are a pretty good deauth primitive for management frame protection networks, so I added it to aircrack-ng: github.com/aircrack-ng/aircrack-ng/…
A screenshot of the new CSA deauth tool running, showing a wpa_supplicant with management frame protection connected to a hostapd with management frame protection getting deauthed. The handshake is captured in shifttymike’s new airodump-ng TUI at the bottom.
022
Reposted by Dominic White
Mark Manning @antitree.com · 03/08/2026
Heading to DEFCON. Couldn't find anyone that made this so I wrote it: A flipper zero NFC canary: keep it in your pocket or bag to keep track and alarm when someone tries to scan your gear while you're walking around the con. github.com/antitree/nfc...
0101
Dominic White @singe.bsky.social · 02/08/2026
Those “public wifi is fine now” people are going to hate Microsoft’s good advice for the SVR abuses of hospitality captive portals. www.microsoft.com/en-us/securi... “When traveling, users should treat hotel, conference, airport, & other guest wireless networks as untrustworthy.”
microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...
032
Dominic White @singe.bsky.social · 01/08/2026
My fortune cookie is even giving me sh*t about maintaining our WiFi hacking course.
A fortune cookie wrapped that reads “You will obtain you goal if you maintain your course”
040
Dominic White @singe.bsky.social · 01/08/2026
Year 25 of SensePost training at BlackHat, I think this is my 17th time.
160
Dominic White @singe.bsky.social · 30/07/2026
BlackHat airport advertising is up but this is the only one that unintentionally makes any sense to a hacker.
An advert for a hidden speakeasy (lol) with the text “You’re only a password away”
040
Dominic White @singe.bsky.social · 30/07/2026
Just saw a “woke is a mental disorder” shirt, scalded my mouth on a filthy cappuccino I had to negotiate for in a normal cup size, and had several pleasant conversations. Hi America!
010
Dominic White @singe.bsky.social · 29/07/2026
I realised some people* were using a super out-of-date version of hostapd-mana based off the upstream 2.6 branch instead of the newer 2.10 branch. This was probably because I never made the 2.10 branch the main. Well that’s fixed now. github.com/sensepost/ho... * me - see last commit for an eg
github.com
GitHub - sensepost/hostapd-mana: SensePost's modified hostapd for wifi attacks.
SensePost's modified hostapd for wifi attacks. Contribute to sensepost/hostapd-mana development by creating an account on GitHub.
061
Dominic White @singe.bsky.social · 29/07/2026
I always love the care our training ops team puts into our BlackHat training swag but the war games mainframe and WiFi themes are both close to my heart. Thanks Darryn & Andre!
Two T-shirts, several playing cards, a lanyard and sticker all WOPR/Wargames movie themed and the WiFi cards have lots of WiFi references.
022
Dominic White @singe.bsky.social · 29/07/2026
I’ve seen a few dry runs of the absolutely fire talk Reino has prepped for everyone at DEFCON this year. Want to see multiple exploit chains on a widely deployed PED device deemed so impactful the vendor asked us to wait two years to disclose, then catch “Very Pwned” info.defcon.org/defcon34/con...
Everyday billions of credit card transactions are made worldwide, with the vast majority being done on purpose-built card machines. In the USA alone, nearly 400 million transactions are performed per day on these popular devices present in nearly every retail store. In this talk, I’ll focus on a widely deployed Verifone product line of card machines, with an estimated global deployment of over one million units. For several consecutive years I conducted an annual security assessment on these devices, until a pattern emerged: I'd arrive at the assessment, find a fresh set of vulnerabilities, gain root access, and then have Verifone patch the devices — only for me to return the following year and gain root access in a new way. I’ll demonstrate the three separate attack chains I discovered, two of which only required network access to the target. I’ll also detail additional vulnerabilities that could be used to disable hardening features such as grsecurity, including the ability to modify the file system to gain persistent access. Next, I’ll show how an attacker could leverage this access to continuously capture credit card information - contrary to the device’s security claims. Finally, in a homage to trixr4skids' DEF CON 25 talk in which he hacked an older series of Verifone's devices, I'll also run Doom.
111
Reposted by Dominic White
shifttymike.bsky.social @shifttymike.bsky.social · 27/07/2026
It’s the default tool for WiFi hacking but there were a few things that bugged me, so I made it better. Then I made it nicer. Here’s the link: github.com/shifttymike/... Static bins available in releases :)
github.com
046
Dominic White @singe.bsky.social · 27/07/2026
Every time we give our wifi hacking training @blackhatevents.bsky.social, we need to help people understand the vagaries of aircrack's airodump-ng, until now, because @shifttymike.bsky.social fixed it!
A screenshot of the new airodump-ng TUI
230
Dominic White @singe.bsky.social · 25/07/2026
I really like this evaluation matrix from @RoelofTemmingh’s @BSidesJoburg keynote for judging quality in a flood of AI slop. The one that resonated with me in particular was: “Has this person ever paid a cost for being wrong”
010
Reposted by Dominic White
Runa Sandvik @runasand.bsky.social · 23/07/2026
Great writeup from @lorenzofb.bsky.social on the recent OpenAI vs. Hugging Face incident. Turns out it started with a human mistake at OpenAI: someone forgot to set up an isolated environment prior to testing a model; the model went rogue; and attacked Hugging Face. techcrunch.com/2026/07/22/h...
24216
Reposted by Dominic White
stacksmashing @stacksmashing.bsky.social · 22/07/2026
If the sandbox escape was so advanced then publish the details.
0162
Dominic White @singe.bsky.social · 20/07/2026
I put up a writeup of our @sensepost annual artwork up here sensepost.com/blog/2026/se... Free downloads if you like it.
sensepost.com
SensePost | SensePost’s 2026 Artwork
001
Reposted by Dominic White
KL3FT3Z @toxy4ny.bsky.social · 15/07/2026
Redteam tool wednesday’s - 💉 P³ — Shellcode Loader: Process Parameter Poisoning. This loader implements a code injection technique that leverages the Windows Process Parameters structure (PEB). sensepost.com/blog/2026/pr... github.com/Orange-Cyber... #redteam #loader #injection #edr #bypass #windows
sensepost.com
SensePost | Process Parameter Poisoning
001
Reposted by Dominic White
Exploit Code Not People @cooperq.com · 23/06/2026
Hooo boy looks like I was right and quantum computing is gonna be the next grift
9688
Reposted by Dominic White
Daniel Mangum @danielmangum.com · 16/06/2026
let’s build something great this week!
021
Reposted by Dominic White
Dominic White @singe.bsky.social · 13/06/2026
Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768
104
Dominic White @singe.bsky.social · 13/06/2026
Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768
104
Dominic White @singe.bsky.social · 11/06/2026
I audibly eyeroll when most cyber people talk about post-quantum crypto, and it's even worse when they're talking big consulting engagement to do what? - update some openssl packages or makes a TLS key exchange explicit? Now you can give them pqc4free github.com/singe/pqc4free
github.com
GitHub - singe/pqc4free: A script to check whether your Linux apache/nginx server is serving post-quantum safe crypto, and recommend improvements.
A script to check whether your Linux apache/nginx server is serving post-quantum safe crypto, and recommend improvements. - singe/pqc4free
002
Dominic White @singe.bsky.social · 09/06/2026
A quick run through the new iOS 27 beta system settings and I noticed: 1 You need to join a waitlist to access new Siri 2 it now shows what type of WiFi is in use when connected 3 it may not be new - but there’s an “impersonation risk detection” feature that can be shared with apps
100
Reposted by Dominic White
The Shadowserver Foundation @shadowserver.bsky.social · 09/06/2026
Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure! Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows...
2115
Dominic White @singe.bsky.social · 05/06/2026
“I want conflict, I want dissent I want the scene to represent, Our hatred of authority Our fight against complacency” youtube.com/watch?v=spLm30…
000
Dominic White @singe.bsky.social · 03/06/2026
Love me some clankers - a little optimisation to common-substrings for your password cracking pleasure github.com/sensepost/co...
github.com
optimize substring loop bounds in Go implementation · sensepost/common-substr@a43aedc
Rewrite the main substring generation loops to encode the minimum substring length directly in loop bounds instead of checking it inside the inner loop. This removes a hot-path branch for the all/...
000
Reposted by Dominic White
Raphael Mudge @raphaelmudge.bsky.social · 01/06/2026
Relax and unwind in the Tradecraft Garden aff-wg.org/2026/06/01/r... Celebrating one year of Tradecraft Garden. 40 blog posts. ~30 POCs/projects. A lot of thank you's inside. The release itself: stack unwinding data generation, reference relaxation in the linker, and COFF mixing (+disco baby!)
aff-wg.org
Relax and unwind in the Tradecraft Garden
We’re at the 12th release of Crystal Palace and marking one year in the Tradecraft Garden. This release adds reference relaxation to make global references PIC-friendly. I’ve also added stack unwin…
2148
Reposted by Dominic White
pspaul @pspaul95.bsky.social · 02/06/2026
A fun gadget I found recently! The .NET JIT compiler makes sure there are no rwx pages by using a memfd, but that turns file writes into straight shellcode execution 🐚
001
Dominic White @singe.bsky.social · 29/05/2026
Those aren’t version numbers, they’re multipliers to token cost.
020
Reposted by Dominic White
The Official Pulpit of CULT OF THE DEAD COW @cultdeadcow.com · 29/04/2026
copy.fail THANKS, I HATE IT.
copy.fail
Copy Fail — 732 Bytes to Root
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
03815
Dominic White @singe.bsky.social · 19/04/2026
I’m reminded of the disconnect between typical vuln scan/pentest XSS findings and real world exploitation by this write up of Russian exploitation of webmail apps ctrlaltintel.com/threat researc… How do you demonstrate XSS impact beyond the classic alert dialog or cookie stealer?
010
Dominic White @singe.bsky.social · 18/04/2026
Periodic reminder - there’s no easy way to clear tracking cookies and other cruft from iOS apps. But you can do it across all of them with one easy shortcut! It won’t log you out of the app just get rid of the cruft from the in-app browser. prefs:root=SAFARI&path=CLEAR_HISTORY_AND_DATA
011
Dominic White @singe.bsky.social · 16/04/2026
UK gov’s review of Mythos shows it completing challenge of approx 20hrs human expert time & 32 steps 3/10 times using 100M tokens. www.aisi.gov.uk/blog/our-evalu… Opus 4.6 did 28/32 steps max & 100M tokens is approx $900. More for Mythos when/if released.
100
Reposted by Dominic White
SpecterOps @specterops.io · 13/04/2026
BloodHound isn’t just AD anymore. With OpenGraph, it extends into GitHub, Jamf, and more. But most training hasn’t caught up. If you maintain coursework, @mrmurky.bsky.social shares what you should update: ghst.ly/4dzYnFL
ghst.ly
BloodHound Has Changed. Your Course Probably Hasn't. - SpecterOps
Four out of five BloodHound courses are three years out of date. If you create or maintain BloodHound training, here is what to update and how to check if your content reflects the current platform.
061
Reposted by Dominic White
Kevin Beaumont @doublepulsar.com · 13/04/2026
Orgs aiming to implement a Mythos-ready security program when they have a flat network with default creds everywhere and ransomware actors casually logged in.
512119
Reposted by Dominic White
Jorge Liboreiro @jorgeliboreiro.bsky.social · 12/04/2026
🧵 Thread of European leaders reacting to Péter Magyar's victory and Viktor Orbán's defeat. Ursula von der Leyen: "Hungary has chosen Europe. Europe has always chosen Hungary. A country reclaims its European path. The Union grows stronger."
3357100
Reposted by Dominic White
Thomas Fuchs 🫯 @thomasfuchs.at · 10/04/2026
Companies should be required by law to completely open devices when they end support for them www.theguardian.com/technology/2...
theguardian.com
Amazon upsets ebook lovers by ending support for old Kindle devices
Up to 2m e-readers made before 2013 will no longer be able to download new titles
26112
Reposted by Dominic White
Joe Slowik @pylos.co · 10/04/2026
This thread is :chefs kiss:
081