Weekly Update 251

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Between school holidays and a house full of tradies repairing things, there wasn’t a lot a free time this week. That said, I’ve got another gov onto HIBP, snared by 11th MVP award, did a heap of other cyber-things and Charlotte and I even managed to

Continue reading Weekly Update 251

Weekly Update 250

Presently sponsored by: Axonius gives IT and security teams the confidence they need to focus on the bigger picture. Learn more and try it free.

This week is a bit of everything again, although the main difference this time was an update on the COVID situation we’re facing in Australia. We’ve been largely virus-free (relative speaking) but as a result, vaccine rollout has been really slow (as in about 5% of

Continue reading Weekly Update 250

Weekly Update 249

Presently sponsored by: ANY.RUN sandbox reveals a malicious sample in seconds. Try the unique approach with an interactive and easy process of analysis!

A bit of a shorter work week this one as we escaped to a little getaway for a few days. That said, it gave me some nice downtime to continue writing the book and speaking of which, after today’s video we had a regular catch up with Rob

Continue reading Weekly Update 249

Weekly Update 247

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Lots of stuff going on this week, beginning with me losing my mind try to get local control of IoT devices. I’m writing up a much more extensive blog post on this, suffice to say it’s a complete mess and all of the suggestions I’ve had have been well-intentioned, but

Continue reading Weekly Update 247

Weekly Update 246

Presently sponsored by: Credential stuffing is currently the biggest threat to organisations, find out how you can protect your network right now with safepass.me

This week has been absolutely dominated by code contributions to Pwned Passwords. This is such an awesome, humbling experience that so many people have wanted to contribute their time to something that makes online life better for all of us. The challenge I have now is, as expected, managing the

Continue reading Weekly Update 246

Weekly Update 245

Presently sponsored by: Tired of poor coverage and false positives with your DAST scanner? Reinvent web application security. Try Probely today!

This week is the culmination of planning that began all the way back in August last year when I announced the intention to start open sourcing the HIBP code base. Today, it’s finally happened with Pwned Passwords now completely open to all. That’s only been possible with the help of

Continue reading Weekly Update 245

Weekly Update 244

Presently sponsored by: Tired of poor coverage and false positives with your DAST scanner? Reinvent web application security. Try Probely today!

For a week where I didn’t think I had much to talk about, I was surprised by what I ended up with by the time I sat down to broadcast. Turns out there’s always a lot to discuss, and that’s before questions from the live audience as well. As I

Continue reading Weekly Update 244

Weekly Update 243

Presently sponsored by: SecurityFWD. A brand new YouTube show from Varonis. Watch Episode 1: How Far can Wi-Fi Travel?

This one is a real short intro as right now, it hurts to type (copy and paste is earlier 😊): I’m Back at a *REAL* Conference; Dealing with RSI; Shellies and MQTT; My IoT Aircon Hack; Drowning in Data Breaches.

Listen on Apple Podcasts
Get it on Google Play
Download via RSS

References

  1. I’ve been at a real conference this week, with

Continue reading Weekly Update 243

Weekly Update 242

Presently sponsored by: CrowdSec – The open-source massively multiplayer firewall: respond to attacks & share signals across the community. Download it for free.

A fairly hectic week this one, in a large part due to chasing down really flakey network issues that are causing devices (namely Shelly relays) to be inaccessible. I suspect it’s ARP related and as of now, it’s still not fully resolved. You know how much shit breaks in a

Continue reading Weekly Update 242