Weekly Update 394

Presently sponsored by: Kolide ensures only secure devices can access your cloud apps. It’s Device Trust tailor-made for Okta. Book a demo today.

I suggest, based on my experiences with data breaches over the years, that AT&T is about to have a very bad time of it. Class actions following data breaches have become all too common and I’ve written before about how much I despise them. The trouble

Continue reading Weekly Update 394

Weekly Update 393

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A serious but not sombre intro this week: I mentioned at the start of the vid that I had the classic visor hat on as I’d had a mole removed from my forehead during the week, along with another on the back of my hand. Here in Australia,

Continue reading Weekly Update 393

Weekly Update 392

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Let’s get straight to the controversial bit: email address validation. A penny-drop moment during this week’s video was that the native browser address validator rejects many otherwise RFC compliant forms. As an example, I asked ChatGTP about the validity of the pipe symbol during the live

Continue reading Weekly Update 392

Inside the Massive Alleged AT&T Data Breach

Presently sponsored by: Kolide can get your cross-platform fleet to 100% compliance. It’s Zero Trust for Okta. Want to see for yourself? Book a demo.

I hate having to use that word – “alleged” – because it’s so inconclusive and I know it will leave people with many unanswered questions. But sometimes, “alleged” is just where we need to begin and over the course of time, proper attribution is

Continue reading Inside the Massive Alleged AT&T Data Breach

Welcoming the Liechtenstein Government to Have I Been Pwned

Presently sponsored by: Kolide can get your cross-platform fleet to 100% compliance. It’s Zero Trust for Okta. Want to see for yourself? Book a demo.

Over the last 6 years, we’ve been very happy to welcome dozens of national governments to have unhindered access to their domains in Have I Been Pwned, free from cost and manual verification barriers. Today, we’re happy to welcome Liechtenstein’s National Cyber Security Unit

Continue reading Welcoming the Liechtenstein Government to Have I Been Pwned

Weekly Update 390

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

Let me begin by quoting Stefan during the livestream: “​​Turns out having tons of data integrity is expensive”. Yeah, and working with tons of data in a fashion that’s both fast and cost effective is bloody painful. I’m reminded of the old

Continue reading Weekly Update 390

Posted in Uncategorized

Welcoming the German Government to Have I Been Pwned

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

Back in 2018, we started making Have I Been Pwned domain searches freely available to national government cybersecurity agencies responsible for protecting their nations’ online infrastructure. Today, we’re very happy to welcome Germany as the 35th country to use this service, courtesy of their CERTBund department. This

Continue reading Welcoming the German Government to Have I Been Pwned

Weekly Update 389

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How on earth are we still here? You know, that place where breached companies stand up and go all Iraqi information minister on the incident as if somehow, flatly denying the blatantly obvious will make it all go away. It’s the ease of debunking the “no breach

Continue reading Weekly Update 389

Weekly Update 388

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It’s just been a joy to watch the material produced by the NCA and friends following the LockBit takedown this week. So much good stuff from the agencies themselves, not just content but high quality trolling too. Then there’s the whole ecosystem of memes that have

Continue reading Weekly Update 388

Thanks FedEx, This is Why we Keep Getting Phished

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I’ve been getting a lot of those “your parcel couldn’t be delivered” phishing attacks lately and if you’re a human with a phone, you probably have been too. Just as a brief reminder, they look like this:

These get through all the

Continue reading Thanks FedEx, This is Why we Keep Getting Phished