Weekly Update 363

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!

I’m super late pushing out this week’s video, I mean to the point where I now have a couple of days before doing the next one. Travel from the opposite side of the world is the obvious excuse, then frankly, just wanting to hang out with

Continue reading Weekly Update 363

68k Phishing Victims are Now Searchable in Have I Been Pwned, Courtesy of CERT Poland

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!

Last week I was contacted by CERT Poland. They’d observed a phishing campaign that had collected 68k credentials from unsuspecting victims and asked if HIBP may be used to help alert these individuals to their exposure. The campaign began with a typical email requesting more information:

In this

Continue reading 68k Phishing Victims are Now Searchable in Have I Been Pwned, Courtesy of CERT Poland

Data From The Qakbot Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!

Today, the US Justice Department announced a multinational operation involving actions in the United States, France, Germany, the Netherlands, and the United Kingdom to disrupt the botnet and malware known as Qakbot and take down its infrastructure. Beyond just taking down the backbone of the operation, the FBI began actively

Continue reading Data From The Qakbot Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI

Weekly Update 362

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

Somehow in this week’s video, I forgot to talk about the single blog post I wrote this week! So here’s the elevator pitch: Cloudflare’s Turnstile is a bot-killing machine I’ve had enormous success with for the “API” (quoted because it&

Continue reading Weekly Update 362

Fighting API Bots with Cloudflare’s Invisible Turnstile

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

There’s a “hidden” API on HIBP. Well, it’s not “hidden” insofar as it’s easily discoverable if you watch the network traffic from the client, but it’s not meant to be called directly, rather only via the web app.

Continue reading Fighting API Bots with Cloudflare’s Invisible Turnstile

Weekly Update 361

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

This week hasd been manic! Non-stop tickets related to the new HIBP domain subscription service, scrambling to support invoicing and resellers, struggling our way through some odd Stripe things and so on and so forth. It’s all good stuff and there have been very few issues of note

Continue reading Weekly Update 361

All New Have I Been Pwned Domain Search APIs and Splunk Integration

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

I’ve been teaching my 13-year old son Ari how to code since I first got him started on Scratch many years ago, and gradually progressed through to the current day where he’s getting into Python in Visual Studio Code. As I was writing the new domain

Continue reading All New Have I Been Pwned Domain Search APIs and Splunk Integration

Welcome to the New Have I Been Pwned Domain Search Subscription Service

Presently sponsored by: Secure your assets, identity and online accounts with our award-winning ID theft protection. Get started with Aura today.

This is a big one. A massive one. It’s the culmination of a solid 7 months of work that finally, as of now, is live. The full back story is in my blog post from mid-June about The Big 5 Announcements but to save you trawling through all

Continue reading Welcome to the New Have I Been Pwned Domain Search Subscription Service

Weekly Update 359

Presently sponsored by: EPAS by Detack. No EPAS protected password has ever been cracked and won’t be found in any leaks. Give it a try, millions of users use it.

Somewhere in the next few hours from publishing this post, I’ll finally push the HIBP domain search changes live. I’ve been speaking about it a lot in these videos over recent weeks so many of you have already know what it entails, but it’s

Continue reading Weekly Update 359

Weekly Update 358

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

IoT, breaches and largely business as usual so I’ll skip that in the intro to this post and jump straight to the end: the impending HIBP domain search changes. As I say in the vid, I really value people’s feedback on this so if nothing else,

Continue reading Weekly Update 358