Weekly Update 384

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I spent longer than I expected talking about Trello this week, in part because I don’t feel the narrative they presented properly acknowledges their responsibility for the incident and in part because I think the impact of scraping in general is misunderstood. I suspect many of us are

Continue reading Weekly Update 384

Weekly Update 383

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

They’re an odd thing, credential lists. Whether they’re from a stealer as in this week’s Naz.API incident, or just aggregated from multiple data breaches (which is also in Naz.API), I inevitably get some backlash after loading them: “this doesn’t

Continue reading Weekly Update 383

Inside the Massive Naz.API Credential Stuffing List

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It feels like not a week goes by without someone sending me yet another credential stuffing list. It’s usually something to the effect of “hey, have you seen the Spotify breach”, to which I politely reply with a link to my old No, Spotify Wasn’

Continue reading Inside the Massive Naz.API Credential Stuffing List

Weekly Update 382

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

Geez it’s nice to be back in Oslo! This city has such a special place in my heart for so many reasons, not least of which by virtue of being Charlotte’s home town we have so many friends and family here. Add in NDC Security this

Continue reading Weekly Update 382

Weekly Update 381

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

It’s another weekly update from the other side of the world with Scott and I in Rome as we continue a bit of downtime before hitting NDC Security in Oslo next week. This week, Scott’s sharing details of how he and Joe Tiedman registered a domain

Continue reading Weekly Update 381

Weekly Update 380

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

We’re in Paris! And feeling proper relaxed after several days of wine and cheese too, I might add. This was a very impromptu end of 2023 weekly update as we balanced family time with doing the final video for the year. On the cyber side, the constant them

Continue reading Weekly Update 380

Weekly Update 379

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

It’s that time of the year again, time to head from the heat to the cold as we jump on the big plane(s) back to Europe. The next 4 weekly updates will all be from places of varying degrees colder than home, most of them done with

Continue reading Weekly Update 379

Weekly Update 378

Presently sponsored by: Identity theft isn’t cheap. Secure your family with Aura the #1 rated proactive protection that helps keep you safe online. Get started.

I’d say the balloon fetish segment was the highlight of this week’s video. No, seriously, it’s a moment of levity in an otherwise often serious industry. It’s still a bunch of personal info exposed publicly and that suchs regardless of the nature

Continue reading Weekly Update 378

A Decade of Have I Been Pwned

Presently sponsored by: Get insights into malware’s behavior with ANY.RUN: instant results, live VM interaction, fresh IOCs, and configs without limit.

A decade ago to the day, I published a tweet launching what would surely become yet another pet project that scratched an itch, was kinda useful to a few people but other than that, would shortly fade away into the same obscurity as all the other ones I’d

Continue reading A Decade of Have I Been Pwned

Weekly Update 376

Presently sponsored by: Kolide ensures that if a device isn’t secure, it can’t access your apps. It’s Device Trust for Okta. Watch the demo today!

I’m irrationally excited about the new Prusa 3D printer on order, and I think that’s mostly to do with planning for the NDC Oslo talk I plan to do with Elle, my 11-year old daughter. I’m all for getting the kids exposure not just

Continue reading Weekly Update 376