Weekly Update 242

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

A fairly hectic week this one, in a large part due to chasing down really flakey network issues that are causing devices (namely Shelly relays) to be inaccessible. I suspect it’s ARP related and as of now, it’s still not fully resolved. You know how much shit breaks in a

Continue reading Weekly Update 242

Weekly Update 241

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

What. A. Week. Heaps of data breaches, heaps of law enforcement and gov stuff and somehow, I still found time to put even more IP addresses into the house courtesy of even more IoT. I’m not sure if the latter gives me a break from the more professional tech stuff

Continue reading Weekly Update 241

Welcoming the Romanian Government to Have I Been Pwned

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

Today I’m very happy to announce the arrival of the 15th government to Have I Been Pwned, Romania. As of now, CERT-RO has access to query all Romanian government domains across HIBP and subscribe them for future notifications when subsequent data breaches affect aliases on those domains.

Romania joins a

Continue reading Welcoming the Romanian Government to Have I Been Pwned

Welcoming the Luxemburg Government CERT to Have I Been Pwned

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

Continuing my efforts to make more breach data available to governments after data breaches impact their domains, I’m very happy to welcome Luxemburg aboard Have I Been Pwned. More specifically, the CERT of the Grand Duchy of Luxemburg (govcert.lu) now has free API level access to query their national

Continue reading Welcoming the Luxemburg Government CERT to Have I Been Pwned

Data From The Emotet Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI and NHTCU

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

Earlier this year, the FBI in partnership with the Dutch National High Technical Crimes Unit (NHTCU), German Federal Criminal Police Office (BKA) and other international law enforcement agencies brought down what Europol rereferred to as the world’s most dangerous malware: Emotet. This strain of malware dates back as far as

Continue reading Data From The Emotet Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI and NHTCU

Weekly Update 240

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

Lots of bit and pieces this week, most of which is self-explanatory based on the references below. One thing to add though is the outcome of the ClearVoice Surveys breach I live-tweeted during the stream: someone from there did indeed get in touch with me. We spoke on the phone,

Continue reading Weekly Update 240

Weekly Update 239

Presently sponsored by: SecurityFWD. A brand new YouTube show from Varonis. Watch Episode 1: How Far can Wi-Fi Travel?

Geez I’m glad the Facebook stuff was the week before this one! With that (mostly) out of the way, we headed off to Thredbo for a couple of days of mountain biking, hitting trails I’ve only ever snowboarded down before (yes, we get snow in Australia). Back to normality (I

Continue reading Weekly Update 239

Data Breaches, Class Actions and Ambulance Chasing

Presently sponsored by: SecurityFWD. A brand new YouTube show from Varonis. Watch Episode 1: How Far can Wi-Fi Travel?

This post has been brewing for a while, but the catalyst finally came after someone (I’ll refer to him as Jimmy) recently emailed me regarding the LOQBOX data breach from 2020. Their message began as follows:

I am currently in the process of claiming compensation for a severe data breach

Continue reading Data Breaches, Class Actions and Ambulance Chasing

Weekly Update 238

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

“What a shit week”. I stand by that statement in the opening couple of minutes of the video and I write this now at midday on Saturday after literally falling asleep on the couch. The Facebook incident just dominated; everything from processing data to writing code to dozens of media

Continue reading Weekly Update 238

Welcoming the Ukrainian Government to Have I Been Pwned

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

Another month, another national government to bring onto Have I Been Pwned. This time it’s the Ukrainian National Cybersecurity Coordination Center who now has access to monitor all their government domains via API domain search, free of charge.

The Ukraine is now the 13th government to be onboarded to HIBP’s

Continue reading Welcoming the Ukrainian Government to Have I Been Pwned