Weekly Update 411

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

The ongoing scourge that is spyware (or, as it is commonly known, “stalkerware”), and the subsequent breaches that so often befall them continue to amaze me. More specifically, it’s the way they tackle the non-consensual spying aspect of the service which, on the one hand is

Continue reading Weekly Update 411

Begging for Bounties and More Info Stealer Logs

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

TL;DR — Tens of millions of credentials obtained from info stealer logs populated by malware were posted to Telegram channels last month and used to shake down companies for bug bounties under the misrepresentation the data originated from their service.

How many attempted scams do you get each day?

Continue reading Begging for Bounties and More Info Stealer Logs

Weekly Update 410

Presently sponsored by: Automox: Worklets are a big toolbox of small Bash and PowerShell scripts to automate and secure all your endpoints. Check them out!

Who would have thought that just a few hours after recording the previous week’s video, the world would descend into what has undoubtedly become the largest IT outage we’ve ever seen:

Continue reading Weekly Update 410

Weekly Update 408

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

I get the frustration and anger those working at organisations that have been breached feel, and I’ve seen it firsthand in my communications with them on so many prior occasions. They’re the victim of a criminal act and they’re rightly outraged. However… thinking back

Continue reading Weekly Update 408

Weekly Update 407

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It’s a long one this week, in part due to the constant flood of new breaches and disclosures I discuss. I regularly have disclosure notices forwarded to me by followers who find themselves in new breaches, and it’s always fascinating to hear how they’re

Continue reading Weekly Update 407

The State of Data Breaches, Part 2: The Trilogy of Players

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Last week, I wrote about The State of Data Breaches and got loads of feedback. It was predominantly sympathetic to the position I find myself in running HIBP, and that post was mostly one of frustration: lack of disclosure, standoffish organisations, downplaying breaches and the individual breach victims themselves making

Continue reading The State of Data Breaches, Part 2: The Trilogy of Players

Weekly Update 406

Presently sponsored by: Push Security. Stop identity attacks with a browser-based agent that detects and prevents account takeover. Try it free now.

Why does it need to be a crazy data breach week right when I’m struggling with jet lag?! I came home from Europe just as a bunch of the Snowflake-sourced breaches started being publicly dumped, and things went a little crazy. Lots of data to review, lots of

Continue reading Weekly Update 406