Weekly Update 394

Presently sponsored by: Kolide ensures only secure devices can access your cloud apps. It’s Device Trust tailor-made for Okta. Book a demo today.

I suggest, based on my experiences with data breaches over the years, that AT&T is about to have a very bad time of it. Class actions following data breaches have become all too common and I’ve written before about how much I despise them. The trouble

Continue reading Weekly Update 394

Weekly Update 393

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A serious but not sombre intro this week: I mentioned at the start of the vid that I had the classic visor hat on as I’d had a mole removed from my forehead during the week, along with another on the back of my hand. Here in Australia,

Continue reading Weekly Update 393

Weekly Update 392

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Let’s get straight to the controversial bit: email address validation. A penny-drop moment during this week’s video was that the native browser address validator rejects many otherwise RFC compliant forms. As an example, I asked ChatGTP about the validity of the pipe symbol during the live

Continue reading Weekly Update 392

Weekly Update 389

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How on earth are we still here? You know, that place where breached companies stand up and go all Iraqi information minister on the incident as if somehow, flatly denying the blatantly obvious will make it all go away. It’s the ease of debunking the “no breach

Continue reading Weekly Update 389

Weekly Update 388

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It’s just been a joy to watch the material produced by the NCA and friends following the LockBit takedown this week. So much good stuff from the agencies themselves, not just content but high quality trolling too. Then there’s the whole ecosystem of memes that have

Continue reading Weekly Update 388

Weekly Update 387

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It’s Device Trust for Okta. Watch the demo!

It’s a short video this week after a few days in Sydney doing both NDC and the Azure user group. For the most part, I spoke about the same things as I did at NDC Security in Oslo last month… except that since then we’ve had

Continue reading Weekly Update 387

Weekly Update 386

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

Somehow, an hour and a half went by in the blink of an eye this week. The Spoutible incident just has so many interesting aspects to it: loads of data that should never be returned publicly, awesome response time to the disclosure, lacklustre transparency in their disclosure, some really fundamental

Continue reading Weekly Update 386

Weekly Update 385

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

I told ya so. Right from the beginning, it was pretty obvious what “MOAB” was probably going to be and sure enough, this tweet came true:

Continue reading Weekly Update 385

Weekly Update 384

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I spent longer than I expected talking about Trello this week, in part because I don’t feel the narrative they presented properly acknowledges their responsibility for the incident and in part because I think the impact of scraping in general is misunderstood. I suspect many of us are

Continue reading Weekly Update 384

Weekly Update 383

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

They’re an odd thing, credential lists. Whether they’re from a stealer as in this week’s Naz.API incident, or just aggregated from multiple data breaches (which is also in Naz.API), I inevitably get some backlash after loading them: “this doesn’t

Continue reading Weekly Update 383