The work from Mathy and friends showed that malicious channel switch announcements are a pretty good deauth primitive for management frame protection networks, so I added it to aircrack-ng: https://github.com/aircrack-ng/aircrack-ng/pull/2724
Dominic White
@singe.bsky.social
Hacker at Orange Cyberdefense's SensePost Team https://hello.singe.za.net/
 The work from Mathy and friends showed that malicious channel switch announcements are a pretty good deauth primitive for management frame protection networks, so I added it to aircrack-ng: https://github.com/aircrack-ng/aircrack-ng/pull/2724
Heading to DEFCON. Couldn't find anyone that made this so I wrote it: A flipper zero NFC canary: keep it in your pocket or bag to keep track and alarm when someone tries to scan your gear while you're walking around the con. github.com/antitree/nfc...
Those “public wifi is fine now” people are going to hate Microsoft’s good advice for the SVR abuses of hospitality captive portals. www.microsoft.com/en-us/securi... “When traveling, users should treat hotel, conference, airport, & other guest wireless networks as untrustworthy.”
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...
microsoft.com
My fortune cookie is even giving me sh*t about maintaining our WiFi hacking course.
Year 25 of SensePost training at BlackHat, I think this is my 17th time.
BlackHat airport advertising is up but this is the only one that unintentionally makes any sense to a hacker.
Just saw a “woke is a mental disorder” shirt, scalded my mouth on a filthy cappuccino I had to negotiate for in a normal cup size, and had several pleasant conversations. Hi America!
I realised some people* were using a super out-of-date version of hostapd-mana based off the upstream 2.6 branch instead of the newer 2.10 branch. This was probably because I never made the 2.10 branch the main. Well that’s fixed now. github.com/sensepost/ho... * me - see last commit for an eg
GitHub - sensepost/hostapd-mana: SensePost's modified hostapd for wifi attacks.
SensePost's modified hostapd for wifi attacks. Contribute to sensepost/hostapd-mana development by creating an account on GitHub.
github.com
I always love the care our training ops team puts into our BlackHat training swag but the war games mainframe and WiFi themes are both close to my heart. Thanks Darryn & Andre!
I’ve seen a few dry runs of the absolutely fire talk Reino has prepped for everyone at DEFCON this year. Want to see multiple exploit chains on a widely deployed PED device deemed so impactful the vendor asked us to wait two years to disclose, then catch “Very Pwned” info.defcon.org/defcon34/con...
It’s the default tool for WiFi hacking but there were a few things that bugged me, so I made it better. Then I made it nicer. Here’s the link: github.com/shifttymike/... Static bins available in releases :)
github.com
Every time we give our wifi hacking training @blackhatevents.bsky.social, we need to help people understand the vagaries of aircrack's airodump-ng, until now, because @shifttymike.bsky.social fixed it!
I really like this evaluation matrix from @RoelofTemmingh’s @BSidesJoburg keynote for judging quality in a flood of AI slop. The one that resonated with me in particular was: “Has this person ever paid a cost for being wrong”
Great writeup from @lorenzofb.bsky.social on the recent OpenAI vs. Hugging Face incident. Turns out it started with a human mistake at OpenAI: someone forgot to set up an isolated environment prior to testing a model; the model went rogue; and attacked Hugging Face. techcrunch.com/2026/07/22/h...
If the sandbox escape was so advanced then publish the details.
I put up a writeup of our @sensepost annual artwork up here sensepost.com/blog/2026/se... Free downloads if you like it.
SensePost | SensePost’s 2026 Artwork
sensepost.com
It's part of my company so I could be biased, but it's good to see some tech company sharing real art on this sloppy era! https://sensepost.com/blog/2026/senseposts-2026-artwork/
SensePost | SensePost’s 2026 Artwork
sensepost.com
Redteam tool wednesday’s - 💉 P³ — Shellcode Loader: Process Parameter Poisoning. This loader implements a code injection technique that leverages the Windows Process Parameters structure (PEB). sensepost.com/blog/2026/pr... github.com/Orange-Cyber... #redteam #loader #injection #edr #bypass #windows
SensePost | Process Parameter Poisoning
sensepost.com
Hooo boy looks like I was right and quantum computing is gonna be the next grift
Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768
Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768
I audibly eyeroll when most cyber people talk about post-quantum crypto, and it's even worse when they're talking big consulting engagement to do what? - update some openssl packages or makes a TLS key exchange explicit? Now you can give them pqc4free github.com/singe/pqc4free
GitHub - singe/pqc4free: A script to check whether your Linux apache/nginx server is serving post-quantum safe crypto, and recommend improvements.
A script to check whether your Linux apache/nginx server is serving post-quantum safe crypto, and recommend improvements. - singe/pqc4free
github.com
A quick run through the new iOS 27 beta system settings and I noticed: 1 You need to join a waitlist to access new Siri 2 it now shows what type of WiFi is in use when connected 3 it may not be new - but there’s an “impersonation risk detection” feature that can be shared with apps
Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure! Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows...
“I want conflict, I want dissent I want the scene to represent, Our hatred of authority Our fight against complacency” youtube.com/watch?v=spLm30…
Love me some clankers - a little optimisation to common-substrings for your password cracking pleasure github.com/sensepost/co...
optimize substring loop bounds in Go implementation · sensepost/common-substr@a43aedc
Rewrite the main substring generation loops to encode the minimum substring length directly in loop bounds instead of checking it inside the inner loop. This removes a hot-path branch for the all/...
github.com
Relax and unwind in the Tradecraft Garden aff-wg.org/2026/06/01/r... Celebrating one year of Tradecraft Garden. 40 blog posts. ~30 POCs/projects. A lot of thank you's inside. The release itself: stack unwinding data generation, reference relaxation in the linker, and COFF mixing (+disco baby!)
Relax and unwind in the Tradecraft Garden
We’re at the 12th release of Crystal Palace and marking one year in the Tradecraft Garden. This release adds reference relaxation to make global references PIC-friendly. I’ve also added stack unwin…
aff-wg.org
A fun gadget I found recently! The .NET JIT compiler makes sure there are no rwx pages by using a memfd, but that turns file writes into straight shellcode execution 🐚
Shellcode execution as a service! To exploit an argument injection in Jellyfin, we searched and found a gadget in the .NET runtime to turn file writes into code execution. Learn about the bug and this new technique in our blog post: www.sonarsource.com/blog/jellyfi... #appsec #vulnerability