Advertisement · 728 × 90

Posts by Dominic White

I’m reminded of the disconnect between typical vuln scan/pentest XSS findings and real world exploitation by this write up of Russian exploitation of webmail apps ctrlaltintel.com/threat researc…

How do you demonstrate XSS impact beyond the classic alert dialog or cookie stealer?

2 days ago 1 0 0 0

Periodic reminder - there’s no easy way to clear tracking cookies and other cruft from iOS apps. But you can do it across all of them with one easy shortcut! It won’t log you out of the app just get rid of the cruft from the in-app browser.

prefs:root=SAFARI&path=CLEAR_HISTORY_AND_DATA

3 days ago 1 1 0 0

Two conclusions from this - it's an incremental improvement, not a sea change. And $1k per attack won't easily scale. We probably not about to experience "THE VULNPOCALYPSE" but continued incremental improvements in vulnerabilities hunting.

4 days ago 0 2 0 0

UK gov’s review of Mythos shows it completing challenge of approx 20hrs human expert time & 32 steps 3/10 times using 100M tokens. www.aisi.gov.uk/blog/our-evalu…

Opus 4.6 did 28/32 steps max & 100M tokens is approx $900. More for Mythos when/if released.

4 days ago 0 0 1 0
Preview
BloodHound Has Changed. Your Course Probably Hasn't. - SpecterOps Four out of five BloodHound courses are three years out of date. If you create or maintain BloodHound training, here is what to update and how to check if your content reflects the current platform.

BloodHound isn’t just AD anymore. With OpenGraph, it extends into GitHub, Jamf, and more.

But most training hasn’t caught up.

If you maintain coursework, @mrmurky.bsky.social shares what you should update: ghst.ly/4dzYnFL

1 week ago 6 1 0 0
Post image

Orgs aiming to implement a Mythos-ready security program when they have a flat network with default creds everywhere and ransomware actors casually logged in.

1 week ago 121 19 5 2

🧵 Thread of European leaders reacting to Péter Magyar's victory and Viktor Orbán's defeat.

Ursula von der Leyen: "Hungary has chosen Europe. Europe has always chosen Hungary. A country reclaims its European path. The Union grows stronger."

1 week ago 361 100 4 4
Preview
Amazon upsets ebook lovers by ending support for old Kindle devices Up to 2m e-readers made before 2013 will no longer be able to download new titles

Companies should be required by law to completely open devices when they end support for them

www.theguardian.com/technology/2...

1 week ago 63 12 2 0
Advertisement

This thread is :chefs kiss:

1 week ago 9 1 0 0

Can attest, they’re super nice about it if you ask.

1 week ago 1 0 0 0
Post image

Yeah Project Glasswing seems cool and all but when you're screaming from the rooftops about "OUR AI IS SO POWERFUL WE CANT RELEASE IT BECAUSE THE RISKS ARE TOO GREAT" then what you're really doing is product marketing.

1 week ago 36 12 1 0

EDITED* to change the word “truth” in the last sentence to “realistic outcome” to sound less conspiratorial. I don’t believe Anthropic is lying about its capability, but cost is usually the inhibitor.

*BlueSky needs an edit button.

1 week ago 2 0 0 0

100% this. I also don't think they can afford to release it to subscribers on Max plans without tiny limits which would upset the user base. They also want to avoid distillation by the Chinese AI labs.

1 week ago 4 1 0 0

What if Mythos is being overhyped so that Anthropic can develop a higher margin enterprise model instead of the high volume low margin one they’ve pursued until now? This is not to say we can disregard the claim - but let’s wait and see where the truth lies.

1 week ago 8 1 2 0

There is no easy 'just do' in response to the surfacing of latent vulnerability in technology.

Vendors must make the investment to address, test and then release.

Customers then need to patch.

There is no magic - just a sequence of events which now need to take place..

1 week ago 0 1 1 0

FBI IC3 report is out for 2025. Reports from ZA went up by 42% (1075-1532). Small compared to the 1m they received in total. Reported losses since 2022 have doubled from $10 to $20 billion. $1.6b of that is from outside the US (complaints from over 200 countries)

www.ic3.gov/AnnualReport/R…

2 weeks ago 0 0 0 0

Monthly reminder: Many people have a book in them, but it takes a special kind of freak to leave the Land of Laziness, cross the Plains of Procrastination and Insecurity Mountain, find the Blade of No One Made You Do This, and use it to cut your chest open and yank that book out.

2 weeks ago 581 98 29 13
Preview
GitHub - singe/seldon: A tool for interacting with Apple's Foundation model LLM's on Apple Intelligence supported Macs. A tool for interacting with Apple's Foundation model LLM's on Apple Intelligence supported Macs. - singe/seldon

If you’d like to play some more github.com/singe/seldon will also let you speak to it and play with its tool calling ability. By default it ships with web search and a calculator.

2 weeks ago 2 0 1 0
Advertisement
Preview
MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI.

I watched LLMs write full exploit chains years ago. The amazement fades once you hit context limits and have to steer the model through every hard corner. The industry is full of people who just got here and are still in the amazement phase. That's the gap worth watching.

2 weeks ago 6 2 1 0

Walking diagonally between two points is faster than walking in straight lines and right angles.

2 weeks ago 2 0 0 0

Florence Welch and Adele are my go tos for that. Not quite as big and operatic but KT Tunstall and Tracy Chapman. Regina Spektor may be a wild card too?

2 weeks ago 2 0 1 0

Totally worth reading.

3 weeks ago 2 1 0 0
Preview
Your data is everywhere. The government is buying it without a warrant Data brokers buy up huge amounts of information from cell phones and browsers to sell for targeted advertising. But the government, including ICE, also buys the data.

No really, I am not kidding when I say that the data broker industry must be destroyed: www.npr.org/2026/03/25/n...

3 weeks ago 2921 1128 55 59

Thanks James!

4 weeks ago 1 0 0 0

Haha!

4 weeks ago 0 0 0 0

I’ve been fighting a losing battle in my home and the time has come to admit defeat. We’ll be getting a dog. Most likely an Alsatian - I know nothing about dog ownership. Internet - I’m looking for all the advice you care to give!

4 weeks ago 5 0 5 0
Post image Post image

This whole concept in LOTR is one of my favourite parts of the whole book. “Evil fucks up because evil people fundamentally cannot imagine that others are not motivated by the same things as them” is another theme that feels relevant right now

4 weeks ago 7680 1713 141 75
Advertisement

LinkedIn is how I keep track of you too! I’ll have occasion to be in London more often this year - hopefully an in person meetup with Lord Jen.

4 weeks ago 0 0 1 0

@infosecjen.bsky.social Jen! 👀

1 month ago 0 0 1 0
Post image

𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗳𝗼𝗿 𝗔𝗜 𝗶𝘀 𝗰𝗿𝗲𝗮𝘁𝗶𝗻𝗴 𝗮𝗻 𝗲𝘅𝗽𝗲𝗿𝘁𝗶𝘀𝗲 𝗽𝗮𝗿𝗮𝗱𝗼𝘅 - blog.451alliance.com/security-for...

1 month ago 1 1 0 0