Welcoming the German Government to Have I Been Pwned

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

Back in 2018, we started making Have I Been Pwned domain searches freely available to national government cybersecurity agencies responsible for protecting their nations’ online infrastructure. Today, we’re very happy to welcome Germany as the 35th country to use this service, courtesy of their CERTBund department. This

Continue reading Welcoming the German Government to Have I Been Pwned

Weekly Update 389

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How on earth are we still here? You know, that place where breached companies stand up and go all Iraqi information minister on the incident as if somehow, flatly denying the blatantly obvious will make it all go away. It’s the ease of debunking the “no breach

Continue reading Weekly Update 389

Weekly Update 388

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It’s just been a joy to watch the material produced by the NCA and friends following the LockBit takedown this week. So much good stuff from the agencies themselves, not just content but high quality trolling too. Then there’s the whole ecosystem of memes that have

Continue reading Weekly Update 388

Thanks FedEx, This is Why we Keep Getting Phished

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I’ve been getting a lot of those “your parcel couldn’t be delivered” phishing attacks lately and if you’re a human with a phone, you probably have been too. Just as a brief reminder, they look like this:

These get through all the

Continue reading Thanks FedEx, This is Why we Keep Getting Phished

Weekly Update 387

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

It’s a short video this week after a few days in Sydney doing both NDC and the Azure user group. For the most part, I spoke about the same things as I did at NDC Security in Oslo last month… except that since then we’ve had

Continue reading Weekly Update 387

Weekly Update 386

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

Somehow, an hour and a half went by in the blink of an eye this week. The Spoutible incident just has so many interesting aspects to it: loads of data that should never be returned publicly, awesome response time to the disclosure, lacklustre transparency in their disclosure, some really fundamental

Continue reading Weekly Update 386

How Spoutible’s Leaky API Spurted out a Deluge of Personal Data

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

Ever hear one of those stories where as it unravels, you lean in ever closer and mutter “No way! No way! NO WAY!” This one, as far as infosec stories go, had me leaning and muttering like never before. Here goes:

Last week, someone reached it to me

Continue reading How Spoutible’s Leaky API Spurted out a Deluge of Personal Data

Weekly Update 385

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

I told ya so. Right from the beginning, it was pretty obvious what “MOAB” was probably going to be and sure enough, this tweet came true:

Continue reading Weekly Update 385

The Data Breach “Personal Stash” Ecosystem

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I’ve always thought of it a bit like baseball cards; a kid has a card of this one player that another kid is keen on, and that kid has a card the first one wants so they make a trade. They both have a bunch of cards they&

Continue reading The Data Breach “Personal Stash” Ecosystem

Weekly Update 384

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I spent longer than I expected talking about Trello this week, in part because I don’t feel the narrative they presented properly acknowledges their responsibility for the incident and in part because I think the impact of scraping in general is misunderstood. I suspect many of us are

Continue reading Weekly Update 384