Welcoming the Dutch Government to Have I Been Pwned

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Today I’m very happy to welcome the Dutch government to HIBP, marking 24 national CERTs that now have full and free access to API level domain searches. The Nationaal Cyber Security Centrum of the Netherlands (NCSC-NL) now has access to monitor the exposure of government departments across all

Continue reading Welcoming the Dutch Government to Have I Been Pwned

Weekly Update 250

Presently sponsored by: Axonius gives IT and security teams the confidence they need to focus on the bigger picture. Learn more and try it free.

This week is a bit of everything again, although the main difference this time was an update on the COVID situation we’re facing in Australia. We’ve been largely virus-free (relative speaking) but as a result, vaccine rollout has been really slow (as in about 5% of

Continue reading Weekly Update 250

Welcoming the Slovak Republic Government to Have I Been Pwned

Presently sponsored by: Axonius gives IT and security teams the confidence they need to focus on the bigger picture. Learn more and try it free.

Today I’m very happy to welcome the 23rd national government to Have I Been Pwned, the Slovak Republic. As of now, CSIRT.sk has full and free access to query all their government domains via an API that returns all their email addresses impacted by each data breach

Continue reading Welcoming the Slovak Republic Government to Have I Been Pwned

Weekly Update 249

Presently sponsored by: ANY.RUN sandbox reveals a malicious sample in seconds. Try the unique approach with an interactive and easy process of analysis!

A bit of a shorter work week this one as we escaped to a little getaway for a few days. That said, it gave me some nice downtime to continue writing the book and speaking of which, after today’s video we had a regular catch up with Rob

Continue reading Weekly Update 249

Welcoming the Jamaican Government to Have I Been Pwned

Presently sponsored by: ANY.RUN sandbox reveals a malicious sample in seconds. Try the unique approach with an interactive and easy process of analysis!

Recently, I’ve been providing a lot of additional government access to Have I Been Pwned. Today I’m happy to welcome the Jamaica Cyber Incident Response Team (JaCIRT), the 22nd national CERT on HIBP and 11th in the last 4 months. They now have full and free

Continue reading Welcoming the Jamaican Government to Have I Been Pwned

Welcoming the Finnish Government to Have I Been Pwned

Presently sponsored by: Axonius gives IT and security teams the confidence they need to focus on the bigger picture. Learn more and try it free.

Today I’m very happy to welcome the Finnish government to Have I Been Pwned by granting their National Cyber Security Centre full and free access to query their government domains. API access to query their domains will give them greater visibility into the impact of data breaches on the Finnish

Continue reading Welcoming the Finnish Government to Have I Been Pwned

Weekly Update 247

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Lots of stuff going on this week, beginning with me losing my mind try to get local control of IoT devices. I’m writing up a much more extensive blog post on this, suffice to say it’s a complete mess and all of the suggestions I’ve had have been well-intentioned, but

Continue reading Weekly Update 247

Nameless Malware Discovered by NordLocker is Now in Have I Been Pwned

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

I’ve had a couple of cases to date where email addresses compromised by malware then discovered in the course of investigations have been provided to Have I Been Pwned (HIBP). Firstly by the Estonian Central Criminal Police a few years ago, then by the FBI and global counterparts this April

Continue reading Nameless Malware Discovered by NordLocker is Now in Have I Been Pwned

Expanding the Have I Been Pwned Volunteer Community

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Ever notice how there was a massive gap of almost 9 months between announcing the intention to start open sourcing Have I Been Pwned (HIBP) in August last year and then finally a couple of weeks ago, actually taking the first step with Pwned Passwords? Many people certainly noticed the

Continue reading Expanding the Have I Been Pwned Volunteer Community