Monday, September 25, 2023

Weekly Update 366

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteWell that's it, Europe is done! I've spent the week in Prague with highlights including catching up with Josef Prusa,...

Weekly Update 365

Presently sponsored by: 1 in 3 families have been affected by fraud. Secure your personal info with Aura’s award-winning identity protection. Start free trial.It's another week of travels, this time from our "second home", Oslo. That's off the back...

Weekly Update 364

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!I'm in Spain! Alicante, to be specific, where we've spent the last few days...

Weekly Update 363

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!I'm super late pushing out this week's video, I mean to the point where...

68k Phishing Victims are Now Searchable in Have I Been Pwned, Courtesy of CERT Poland

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!Last week I was contacted by CERT Poland. They'd observed a phishing campaign that...

Data From The Qakbot Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI

Presently sponsored by: Fastmail. Check out Masked Email, built with 1Password. One click gets you a unique email address for every online signup. Try it now!Today, the US Justice Department announced a multinational operation involving actions in the United...

Weekly Update 362

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It's Device Trust for Okta. Watch the demo!Somehow in this week's video, I forgot to talk about the single blog...

Fighting API Bots with Cloudflare’s Invisible Turnstile

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It's Device Trust for Okta. Watch the demo!There's a "hidden" API on HIBP. Well, it's not "hidden" insofar as it's...

Weekly Update 361

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It's Device Trust for Okta. Watch the demo!This week hasd been manic! Non-stop tickets related to the new HIBP domain...

All New Have I Been Pwned Domain Search APIs and Splunk Integration

Presently sponsored by: Unpatched devices keeping you up at night? Kolide can get your entire fleet updated in days. It's Device Trust for Okta. Watch the demo!I've been teaching my 13-year old son Ari how to code since I...

Weekly Update 360

Presently sponsored by: Secure your assets, identity and online accounts with our award-winning ID theft protection. Get started with Aura today.So about those domain searches... 😊 The new subscription model launched this week and as many of you know...

Welcome to the New Have I Been Pwned Domain Search Subscription Service

Presently sponsored by: Secure your assets, identity and online accounts with our award-winning ID theft protection. Get started with Aura today.This is a big one. A massive one. It's the culmination of a solid 7 months of work that...

Weekly Update 359

Presently sponsored by: EPAS by Detack. No EPAS protected password has ever been cracked and won't be found in any leaks. Give it a try, millions of users use it.Somewhere in the next few hours from publishing this post,...

Weekly Update 358

Presently sponsored by: Kolide ensures that if a device isn't secure, it can't access your apps. It's Device Trust for Okta. Watch the demo today!IoT, breaches and largely business as usual so I'll skip that in the intro to...

Weekly Update 357

Presently sponsored by: Kolide ensures that if a device isn't secure, it can't access your apps. It's Device Trust for Okta. Watch the demo today!Sad news to wake up to today. Kevin was a friend and as I say...

Weekly Update 356

Presently sponsored by: Americans lost $8.8B to identity theft in 2022. Secure your online info with Aura the #1 rated identity theft protection. Start free trial.Today was a bit back-to-back having just wrapped up the British Airways Magecart attack...

Lucky MVP 13

Presently sponsored by: Americans lost $8.8B to identity theft in 2022. Secure your online info with Aura the #1 rated identity theft protection. Start free trial.Each year since 2011, Microsoft has sent me a lovely email around this time:I've...

Weekly Update 355

Presently sponsored by: EPAS by Detack. No EPAS protected password has ever been cracked and won't be found in any leaks. Give it a try, millions of users use it.Alrighty, "The Social Media". Without adding too much here as...

Weekly Update 354

Presently sponsored by: Kolide can get your cross-platform fleet to 100% compliance. It's Zero Trust for Okta. Want to see for yourself? Book a demo.I'm in Thailand! It's spectacular here, and even more so since recording this video and...

Weekly Update 353

Presently sponsored by: Kolide can get your cross-platform fleet to 100% compliance. It's Zero Trust for Okta. Want to see for yourself? Book a demo.This feels like a week of minor frustrations with little real world consequence but they...
Infosecurity Magazine

BEC Scammer Pleads Guilty to Part in $6m Scheme

Nigerian was extradited to the US from Canada
Infosecurity Magazine

Researchers Spot Novel “Deadglyph” Backdoor

Malware is linked to UAE-backed spies
Infosecurity Magazine

Almost US 900 Schools Breached Via MOVEit

National Student Clearinghouse reveals more details of incident

Don’t Get Burned by CAPTCHAs: A Recipe for Accurate Bot Protection

Traditional CAPTCHAs, such as reCAPTCHA, no longer protect online businesses adequately. Real users hate them. Bots bypass them. It's time to upgrade.
The Hacker News

New Report Uncovers Three Distinct Clusters of China-Nexus Attacks on Southeast Asian Government

An unnamed Southeast Asian government has been targeted by multiple China-nexus threat actors as part of espionage campaigns targeting the region over extended periods of time. "While this activity occurred around the same time and in some instances even simultaneously...