Weekly Update 396

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

“More Data Breaches Than You Can Shake a Stick At”. That seems like a reasonable summary and I suggest there are two main reasons for this observation. Firstly, there are simply loads of breaches happening and you know this already because, well, you read my stuff! Secondly, There

Continue reading Weekly Update 396

Weekly Update 395

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Data breach verification: that seems like a good place to start given the discussion in this week’s video about Accor. Watch the vid for the whole thing but in summary, data allegedly taken from Accor was published to a popular hacking forum and the headlines inevitably followed. However,

Continue reading Weekly Update 395

Weekly Update 394

Presently sponsored by: Kolide ensures only secure devices can access your cloud apps. It’s Device Trust tailor-made for Okta. Book a demo today.

I suggest, based on my experiences with data breaches over the years, that AT&T is about to have a very bad time of it. Class actions following data breaches have become all too common and I’ve written before about how much I despise them. The trouble

Continue reading Weekly Update 394

Weekly Update 393

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A serious but not sombre intro this week: I mentioned at the start of the vid that I had the classic visor hat on as I’d had a mole removed from my forehead during the week, along with another on the back of my hand. Here in Australia,

Continue reading Weekly Update 393

Weekly Update 392

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Let’s get straight to the controversial bit: email address validation. A penny-drop moment during this week’s video was that the native browser address validator rejects many otherwise RFC compliant forms. As an example, I asked ChatGTP about the validity of the pipe symbol during the live

Continue reading Weekly Update 392

Inside the Massive Alleged AT&T Data Breach

Presently sponsored by: Kolide can get your cross-platform fleet to 100% compliance. It’s Zero Trust for Okta. Want to see for yourself? Book a demo.

I hate having to use that word – “alleged” – because it’s so inconclusive and I know it will leave people with many unanswered questions. But sometimes, “alleged” is just where we need to begin and over the course of time, proper attribution is

Continue reading Inside the Massive Alleged AT&T Data Breach

Welcoming the Liechtenstein Government to Have I Been Pwned

Presently sponsored by: Kolide can get your cross-platform fleet to 100% compliance. It’s Zero Trust for Okta. Want to see for yourself? Book a demo.

Over the last 6 years, we’ve been very happy to welcome dozens of national governments to have unhindered access to their domains in Have I Been Pwned, free from cost and manual verification barriers. Today, we’re happy to welcome Liechtenstein’s National Cyber Security Unit

Continue reading Welcoming the Liechtenstein Government to Have I Been Pwned

Weekly Update 390

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

Let me begin by quoting Stefan during the livestream: “​​Turns out having tons of data integrity is expensive”. Yeah, and working with tons of data in a fashion that’s both fast and cost effective is bloody painful. I’m reminded of the old

Continue reading Weekly Update 390

Posted in Uncategorized

Welcoming the German Government to Have I Been Pwned

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

Back in 2018, we started making Have I Been Pwned domain searches freely available to national government cybersecurity agencies responsible for protecting their nations’ online infrastructure. Today, we’re very happy to welcome Germany as the 35th country to use this service, courtesy of their CERTBund department. This

Continue reading Welcoming the German Government to Have I Been Pwned

Weekly Update 389

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How on earth are we still here? You know, that place where breached companies stand up and go all Iraqi information minister on the incident as if somehow, flatly denying the blatantly obvious will make it all go away. It’s the ease of debunking the “no breach

Continue reading Weekly Update 389