Weekly Update 415

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

I still find the reactions to the Telegram situation with Durov’s arrest odd. There are no doubt all sorts of politics surrounding it, but even putting all that aside for a moment, the assertion that a platform provider should not be held accountable for moderating content on the

Continue reading Weekly Update 415

The North American Have I Been Pwned Tour

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

It was 2019 that I was last in North America, spending time in San Francisco, Los Angeles, Vegas, Denver, Minnesota, New York and Seattle. The year before, it was Montreal and Vancouver and since then, well, things got a bit weird for a while. It’s a shame it&

Continue reading The North American Have I Been Pwned Tour

Posted in Uncategorized

The Trouble with Procurement Departments, Resellers and Stripe

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

It should be so simple: you’re a customer who wants to purchase something so you whip out the credit card and buy it. I must have done this thousands of times, and it’s easy! I’ve bought stuff with plastic credit cards, stuff with Apple

Continue reading The Trouble with Procurement Departments, Resellers and Stripe

Posted in Uncategorized

Weekly Update 413

Presently sponsored by: SentinelOne: Our agentless Offensive Security Engine automates red-teaming, without the false positives. This blog shows how.

Whilst there definitely weren’t 2.x billion people in the National Public Data breach, it is bad. It really is fascinating how much data can be collected and monetised in this fashion and as we’ve seen many times before, data breaches do often follow. The NPD

Continue reading Weekly Update 413

Inside the “3 Billion People” National Public Data Breach

Presently sponsored by: SentinelOne: Our agentless Offensive Security Engine automates red-teaming, without the false positives. This blog shows how.

I decided to write this post because there’s no concise way to explain the nuances of what’s being described as one of the largest data breaches ever. Usually, it’s easy to articulate a data breach; a service people provide their information to had someone

Continue reading Inside the “3 Billion People” National Public Data Breach

Weekly Update 411

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

The ongoing scourge that is spyware (or, as it is commonly known, “stalkerware”), and the subsequent breaches that so often befall them continue to amaze me. More specifically, it’s the way they tackle the non-consensual spying aspect of the service which, on the one hand is

Continue reading Weekly Update 411

Begging for Bounties and More Info Stealer Logs

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

TL;DR — Tens of millions of credentials obtained from info stealer logs populated by malware were posted to Telegram channels last month and used to shake down companies for bug bounties under the misrepresentation the data originated from their service.

How many attempted scams do you get each day?

Continue reading Begging for Bounties and More Info Stealer Logs