Dominic White
@singe.bsky.social
š¤ 1191
š„ 760
š 602
Hacker at Orange Cyberdefense's SensePost Team
https://hello.singe.za.net/
Eulogy for a Beggar Driving home each day, Iād meet a young beggar. Today he wasnāt there. His friend said he passed on. Traffic flowed past where he once stood, unbothered by the person that once disturbed it. What do you say about a life you never knew; mourn it & wonder how I could have saved it?
1 day ago
0
1
0
reposted by
Dominic White
James Kettle
2 days ago
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring!
apply.workable.com/portswigger/...
0
8
8
reposted by
Dominic White
Renaud Lifchitz ā µ
2 days ago
Overrun with AI slop, cURL scraps bug bounties to ensure "intact mental health"
https://arstechnica.com/security/2026/01/overrun-with-ai-slop-curl-scraps-bug-bounties-to-ensure-intact-mental-health/
0
1
1
reposted by
Dominic White
Laurent Cheylus
3 days ago
GPU Code can now use Rust's standard library. Blog Post by VectorWare about the Implementation Approach and what this unlocks for GPU Programming.
#Rust
#GPU
www.vectorware.com/blog/rust-st...
loading . . .
Rust's standard library on the GPU
GPU code can now use Rust's standard library. We share the implementation approach and what this unlocks for GPU programming.
https://www.vectorware.com/blog/rust-std-on-gpu/
0
2
1
reposted by
Dominic White
Acyn
5 days ago
Jennings: Let's not get our knickers in a twist here McGowan: Why are you talking like that? It's insane. Your attitude is just horrifyingā¦
loading . . .
2551
28155
8777
reposted by
Dominic White
SecByTĢ·Ķ̽Ķ̼̯ĢĢĶĶo̶ĶĢæĶĢĢĢĢĶĢ Ģ°Ķ̩̻Ģ̰mĢ·ĢĶĢĢĢ”Ģ
10 days ago
If your SOC doesnāt already alert on NetNTLM with challenges of ā1122334455667788ā you should fix that NOW.
cloud.google.com/blog/topics/...
loading . . .
Releasing Rainbow Tables to Accelerate Protocol Deprecation | Google Cloud Blog
Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1.
https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables
1
4
5
reposted by
Dominic White
tmp0ut
11 days ago
We are excited to announce the CFP for the next tmp.0ut Volume 5!
tmpout.sh/blog/vol5-cf...
0
28
16
Weāve crossed the rubicon where for many simple tech use cases itās easier to vibe code exactly what you want than it is to research several existing solutions and test them.
6 days ago
0
2
0
In Portswigger's Burp I needed a way to do Match & Replace globally across all utilities, not just the proxy so I wrote an extension
github.com/singe/burp_g...
6 days ago
0
4
0
reposted by
Dominic White
Darren Olivier
6 days ago
This story makes the point that thereās little appetite within BRICS (or BRICS+) for it to be a security alliance. Exercise āWill For Peaceā is no more a BRICS exercise than IBSAMAR, the biennial naval exercise South Africa has with India & Brazil, is.
www.scmp.com/week-asia/po...
loading . . .
Testing the waters: is Brics evolving into a security alliance?
The first naval exercises under the āBrics plusā banner saw Brazil, Egypt, China, Russia and South Africa take part. India did not.
https://www.scmp.com/week-asia/politics/article/3340195/will-peace-drills-brics-tests-waters-military-cooperation
0
3
1
reposted by
Dominic White
Dare Obasanjo
7 days ago
Insights from Ben Affleck on AI: ⢠AI can help write scenes but can't create full movies. ⢠Job loss fears are overblown because adoption of new tech is slow; it's hype for startup valuations. ⢠ChatGPT v5 is ~25% better but costs 4x. ⢠Users actually preferred v4's sycophancy for companionship.
loading . . .
32
571
158
The number of times people have tried to kill Net-NTLMv1 eh?
youtu.be/lm7Cuktpnb4?...
9 days ago
1
5
2
reposted by
Dominic White
about 2 months ago
What are the Wi-Fi capabilities of all iPhone 17 models and Apple N1 wireless chip? I profiled all iPhone 17 models so that you don't have to.
www.jiribrejcha.net/2025/11/wi-f...
#WiFi7
#iPhone17
#N1
#AppleN1
#WLANPi
#Profiler
1
6
4
Is it corruption or stupidity driving this spectacular shot to the diplomatic phallus by South Africa
loading . . .
SANDF apparently defied presidential orders to remove Iran from a joint naval exercise
The SA National Defence Force (SANDF) appears to have defied orders from President Ramaphosa to withdraw three Iranian warships from the multinational naval exercise Will for Peace taking place in Fal
https://www.dailymaverick.co.za/article/2026-01-14-sandf-apparently-defied-presidential-ordorders-to-remove-iran-from-a-joint-naval/
10 days ago
0
0
0
Iām genuinely wondering what the end game of the current round of tech balkanisation is. The US sanctioning of ICC officials shows that separate datacentres arenāt enough like they were for privacy safe harbour. But customers mostly donāt want to pay a premium for isolated legal & technical entities
10 days ago
0
0
0
The difference between flat burr and conical burr ground espresso is surprisingly large! I honestly didnāt think it made that much difference and it was just espresso needs going deep - but even normals can taste a clear difference.
10 days ago
1
2
0
First day back to work from summer vacation and I feel guilty about how much positivity I feel in me, and the people around me. I donāt know if itās a whole South Africa vibe - but it feels like this is the year things get better this side. Please donāt make me quote post this later with a sad face.
10 days ago
0
3
0
reposted by
Dominic White
Rep. Ted Lieu
17 days ago
There is no legal justification, whatsoever, to use military force against a NATO ally like Greenland. If any military member participates in this without congressional authorization, they are following illegal orders.
loading . . .
136
2916
1313
reposted by
Dominic White
Joseph Menn
10 days ago
Setting aside the reversal of policy and the possibly deliberate scare message, reporters need to adjust their threat models and get their operational security nailed down. The stakes are extremely high. Gift link from the marketing people.
wapo.st/4pFh6lw
loading . . .
FBI executes search warrant at Washington Post reporterās home
The search came as part of an investigation into a government contractor accused of illegally retaining classified government materials.
https://wapo.st/4pFh6lw
1
44
29
reposted by
Dominic White
Nosferatu Joseph š§š»āāļø
12 days ago
My favourite "this would have been a great day on Bluesky" media moment from history.
3
13
3
reposted by
Dominic White
Ulrike Franke
13 days ago
Joint statement by 4 former officials in Democratic and Republican Administrationsāincluding four NATO Ambassadors, 3 Assistant Secretaries of State for Europe, and 3 NSC Senior Directors. Excellent opening in particular.
loading . . .
Americaās Strategic Alliance with Denmark and NATO
A statement by 14 former officials in Democratic and Republican Administrationsāincluding four NATO Ambassadors, 3 Assistant Secretaries of State for Europe, and 3 NSC Senior Directors
https://newsletter.ivodaalder.com/p/americas-strategic-alliance-with?utm_medium=email
44
913
437
reposted by
Dominic White
Filippo Valsorda
14 days ago
I endorse everything in this post. Iām also processing the fact that programming has permanently changed, but denying or āopposingā it is not going to make the best of it.
add a skeleton here at some point
4
73
8
reposted by
Dominic White
Rebecca Watson
14 days ago
In case youāre wondering whether the pro-ICE reactions to Renee Nicole Goodās murder are natural, hereās a comment that was just left on my video. My video about anti-transgender bias at the BBC. I havenāt made a video about Good yet.
youtu.be/pWm3dK8tPto
119
7133
1923
reposted by
Dominic White
Claire Nevin-Field
15 days ago
āI have asked the clergy of the diocese to make sure their affairs are in order and they have written their wills.,not the time for statements. It is time to put our bodies between the powers of this world and the most vulnerableā. Rob Hirschfeld, Bishop of the Episcopal Diocese of New Hampshire
loading . . .
Redirecting...
https://www.facebook.com/share/p/17wvjFV4yX/
85
5203
1686
reposted by
Dominic White
Carl Quintanilla
16 days ago
GERMAN PRESIDENT STEINMEIER: ā.. the United States has broken with the values that it helped to establish .. ā.. we have now moved beyond the stage where we can lament the lack of respect for international law or the erosion of the international order; we are far beyond that, I believe.ā
loading . . .
367
12219
4954
reposted by
Dominic White
Joseph Cox
17 days ago
New: we've obtained material explaining how an ICE surveillance system, called Webloc, works. Draw shape on a map, see all phones available there, follow them home. All without warrant āThis is a very dangerous tool in the hands of an out-of-control agency.ā
www.404media.co/inside-ices-...
loading . . .
Inside ICEās Tool to Monitor Phones in Entire Neighborhoods
404 Media has obtained material that explains how Tangles and Webloc, two surveillance systems ICE recently purchased, work. Webloc can track phones without a warrant and follow their owners home or t...
https://www.404media.co/inside-ices-tool-to-monitor-phones-in-entire-neighborhoods/
149
6984
5126
reposted by
Dominic White
Jake Williams
19 days ago
The same Republican state legislatures that passed age verification laws for porn are silent on Grok creating and publishing CSAM. It was never about the children.
0
117
53
reposted by
Dominic White
21 days ago
I find the US taking Maduro to be entirely in-character (remember Noreaga?). The weird part is having just pardoned Hernandez after he did the same thing.
5
22
2
reposted by
Dominic White
Nicolas GrƩgoire
25 days ago
Annaās Archive is an incredible project aimed at preserving humanityās knowledge and culture Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens š¶
annas-archive.org/blog/backing...
loading . . .
Backing up Spotify
We backed up Spotify (metadata and music files). Itās distributed in bulk torrents (~300TB). Itās the worldās first āpreservation archiveā for music which is fully open (meaning it can easily be mirro...
https://annas-archive.org/blog/backing-up-spotify.html
0
13
6
Happy 0x7ea Nerds!
24 days ago
0
3
0
reposted by
Dominic White
Securityish
24 days ago
The European Space Agency (ESA) has reported a security incident involving the potential breach of external servers, with cybercriminals claiming to have stolen over 200 GB of data. This includes confidential documents, source code, and access tokens, allegedly obtained between December 18 - 25.
0
2
1
reposted by
Dominic White
maia arson crimew š“
28 days ago
gpg.fail
7
255
70
reposted by
Dominic White
Filippo Valsorda
29 days ago
At the
gpg.fail
talk and omg
#39c3
You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Wonāt even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet.
4
440
134
reposted by
Dominic White
Etienne Stalmans
29 days ago
I'm not šÆ on what the CVE was issued for in the end. The ActiveX bypass is still present (along with ProtectedView bypass), the fix was to disable the functionality in Outlook. It is why APT34 and APT33 were able to continue using it by re-enabling the functionality:
cloud.google.com/blog/topics/...
loading . . .
Breaking the Rules: A Tough Outlook for Home Page Attacks (CVE-2017-11774) | Mandiant | Google Cloud Blog
https://cloud.google.com/blog/topics/threat-intelligence/breaking-the-rules-tough-outlook-for-home-page-attacks/
0
2
1
reposted by
Dominic White
Filippo Valsorda
about 1 month ago
Really big age release coming tomorrow! š š» - native post-quantum keys - built-in recipients for hw plugins - age-inspect tool - plugin framework - batchpass plugin - many improved error messages
loading . . .
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/age
https://age-encryption.org
0
120
23
We (Orange Cyberdefense) became a CVE CNA & in prep for that collected the various vulns we had reported over the years that had corresponding public information. 108 of them! Itās mostly a vanity list but will be where we publish new vulns in future.
advisories.orangecyberdefense.com/advisories
about 1 month ago
1
6
0
reposted by
Dominic White
The Alan Turing Institute
about 1 month ago
š» How far can we push small language models? This summer, our Project t0 team showed that small, open-weight language models can achieve near-frontier reasoning performance when applied to focused, domain-specific tasks.
http://bit.ly/4fu00E1
loading . . .
Why we still need small language models ā even in the age of frontier AI
Lean, locally run models can unlock huge benefits for public sector and compute-constrained environments
http://bit.ly/4fu00E1
0
30
8
Barbra Streisand Wooo, wooo, wooo-ooh, wooo, wooo, wooo-ooh Wooo, wooo, wooo-ooh, wooo, wooo, wooo Barbra Streisand I never watch 60 minutes but I watched that one about CECOT wooo Barbra Streisand
about 1 month ago
0
3
1
reposted by
Dominic White
The Hacker's Choice (1995)
about 1 month ago
THC Release š„: The worldās largest IP<>Domain database:
ip.thc.org
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free. Updated monthly. Try: curl
ip.thc.org/1.1.1.1
Raw data (187GB):
ip.thc.org/docs/bulk-da...
(The fine work of messede š)
0
44
21
reposted by
Dominic White
r1cksec
about 1 month ago
This function takes a tenant ID and queries the public
accounts.accesscontrol.windows.net
metadata (returns all domains associated with that Office 365 tenant)šµļøāāļø
github.com/gscales/Powe...
#infosec
#cybersecurity
#redteam
#osint
#cloud
loading . . .
Sign in to your account
https://accounts.accesscontrol.windows.net
0
5
3
reposted by
Dominic White
Taggart
about 1 month ago
This is super good news: Docker Hardened Images are now available for free for all devs. These can form a much more secure baseline of your containerized apps.
loading . . .
Hardened Images for Everyone | Docker
Security for everyone. Docker Hardened Images are now free to use, share, and build on with no licensing surprises.
https://www.docker.com/blog/docker-hardened-images-for-every-developer/
0
7
6
reposted by
Dominic White
Jeff Moss
about 1 month ago
I just realized if you set your iPhone to be used by an underage user you can override app advertising that you canāt override as an adult iPhone user. That seems useful, has anyone done this? Any issues to consider?
#iphone
#privacy
1
11
14
reposted by
Dominic White
Cynthia Brumfield
about 1 month ago
Assassination plots, sabotage, cyber-attacks and the manipulation of information by Russia and other hostile states mean that āthe frontline is everywhereā, the new head of MI6 will warn on Monday.
www.theguardian.com/uk-news/2025...
loading . . .
āThe frontline is everywhereā: new MI6 head to warn of growing Russian threat
Blaise Metreweli expected to say UK faces new āage of uncertaintyā in speech identifying Kremlin as key threat
https://www.theguardian.com/uk-news/2025/dec/15/new-mi6-head-blaise-metreweli-speech-russia-threat
0
4
2
reposted by
Dominic White
The Hacker's Choice (1995)
about 1 month ago
THC Release: šSmallest SSHD backdoorš - Does not add any new file - Survives apt-update - Does not use PAM or authorized_keys Just SSHD trickery....adds one line only. More at
thc.org/tips
š
0
17
4
reposted by
Dominic White
Deth Veggie
about 1 month ago
And, AGAIN -- Another good opportunity to remind you of Deth Veggie's First Law of the Internet: LIE TO EVERY SITE ABOUT ABSOLUTELY EVERYTHING YOU CAN. Fake names, fake birthdays, fake pets' names, and maiden names, and first streets, and schools and... everything you can.
5
18
4
reposted by
Dominic White
Dale Nunns
about 2 months ago
My BSides Cape Town 2025 wrap-up is finally out, you can read about it all here
www.linkedin.com/pulse/bsides...
. Please share with your friends and help spread the word!
#bsidescapetown2025
#bsidescapetown
#hackers
#rubberducks
loading . . .
BSides Cape Town 2025 - 14000 steps by the sea.
Saturday 6th December 2025 was BSides Cape Town 2025! Our yearly hacker/infosec/security/"cyber" conference. This year it was bigger than ever with over 600 people (I think it was as high as 640?), wi...
https://www.linkedin.com/pulse/bsides-cape-town-2025-14000-steps-sea-dale-nunns-gujgf/
0
1
2
reposted by
Dominic White
š„ leonjza
about 2 months ago
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool.
sensepost.com/blog/2025/pw...
sensepost.com/blog/2025/pi...
0
3
2
reposted by
Dominic White
š„ leonjza
about 2 months ago
Itās almost time for my @BSidesCapeTown talk, and Iāve just open sourced pipetap. My Windows named pipe proxy & multi-tool. Excited to see what you do with it!
github.com/sensepost/pi...
add a skeleton here at some point
0
12
5
lolwifi.network
really does point out the elephant in the cyber room. Itās not about WiFi itās about security professionals understanding risk assessment.
loading . . .
lolwifi.network - Public WiFi Security Assessment
Public WiFi security assessment and education. Understand the risks that occur when joining networks.
https://lolwifi.network
about 2 months ago
1
5
2
Load more
feeds!
log in