Weekly Update 523: Live From a Norwegian Fjord

Presently sponsored by: If an AI agent caused an incident tomorrow, what evidence could you produce? Origin and analyst firm SACR answer it live Oct 1. Register.

How’s that view?! With NDC Oslo now done, it’s a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott’s and my “Cyber-broken” talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both

Continue reading Weekly Update 523: Live From a Norwegian Fjord→

Weekly Update 522: Live From Oslo with Scott Helme

Presently sponsored by: SACR’s Endpoint Control and Prevention report, live Oct 1 with its author and Origin’s founder, deep on endpoint AI observability. Register.

Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving – sorry! But get through that and have a listen to Scott’s experiences with how Report URI is identifying malware-infected machines within orgs, all due to CSP reporting. It&

Continue reading Weekly Update 522: Live From Oslo with Scott Helme→

Weekly Update 521: Breach Perception v. Reality

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There’s the stat I talk about where it’s had literally 0%

Continue reading Weekly Update 521: Breach Perception v. Reality→

Weekly Update 520: The Unscripted Edition

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I’ve started playing around with YouTube’s “create video thumbnail”, which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it&

Continue reading Weekly Update 520: The Unscripted Edition→

Weekly Update 519: Breaches & Data Integrity

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It does feel like I’ve bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the “normal” NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ratbag hackers keep dumping more

Continue reading Weekly Update 519: Breaches & Data Integrity→

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

You’re not going to believe this, but turns out you can’t always take criminals at their word. Actually, I’ll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here:

Continue reading A Cautionary Tale About Data Breach Claims, Verification and Carhartt→

Weekly Update 518: IoT Doorlock Nirvana with UniFi

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I genuinely think I’ve nailed the IoT door lock situation! Well, Ubiquiti has, but I think I’ve worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:

  1. Main power (never have to rely on

Continue reading Weekly Update 518: IoT Doorlock Nirvana with UniFi→

Welcoming the Sri Lankan Government to Have I Been Pwned

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

Continue reading Welcoming the Sri Lankan Government to Have I Been Pwned→

Weekly Update 517: Cyber Ransoms

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn’t even involve “ware”, it’s just extortion) is carried out by kids who successfully make a truckload of money but can’t spend it without

Continue reading Weekly Update 517: Cyber Ransoms→

Weekly Update 516: Live From Vietnam

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it’s the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to

Continue reading Weekly Update 516: Live From Vietnam→