Have I Been Pwned
Learn how Have I Been Pwned uses Report URI to monitor their site for Malicious JavaScript and unauthorised Data Exfiltration!
Read MoreCustomer stories, notable attacks, and organisations running a Content Security Policy in production.
Learn how Have I Been Pwned uses Report URI to monitor their site for Malicious JavaScript and unauthorised Data Exfiltration!
Read MoreA support ticket containing a linked file reached 275 million student records — and four days passed before anyone noticed the stolen session.
Read More$1.46 billion — the largest theft in the asset class's history — began with a modified JavaScript file, served to a single wallet and removed two minutes later.
Read MoreThe United States Courts were infected with Cryptojacking Malware that used visitor's browsers to mine Cryptocurrency for the attackers.
Read MoreEight lines of JavaScript skimmed Newegg’s checkout for 35 days in 2018 — the same group as British Airways, with the code cut to a third of the size.
Read MoreTicketmaster were targeted by Magecart in an attack via a 3rd-party dependency. Learn how Report URI could have helped and saved millions in damages.
Read MoreA spearphishing email injected JavaScript into the victim’s open webmail page. Nothing touched disk for endpoint tooling to find.
Read MoreA dependency 100,000 sites trusted changed hands and started serving malicious code. Nothing on any of those sites changed.
Read MoreThe ESA was infected with Magecart which resulted in the organisation having to take down certain infrastructure.
Read MoreAn unauthenticated request wrote JavaScript into a device name, to fire later in an admin dashboard with authority over every managed endpoint.
Read MoreCVE-2024-34102 was used to skim 4,275 Adobe Commerce and Magento stores. Applying the patch did not stop it, because the stolen keys stayed valid.
Read MoreOne modified platform library reached 6,589 merchant stores. None of them were breached, and 239,000 cards were later sold.
Read MoreThe Information Commissioner's Office was the victim of a Cryptojacking Attack that could have been detected and even stopped using Report URI.
Read MoreExploited as a zero-day for six weeks, then again after the patch made it public. The payload stole the authentication token, not the mail.
Read MoreA day after Claire’s closed 3,000 stores for lockdown, attackers registered their exfiltration domain. The skimmer ran for six to seven weeks, disguised as an image request.
Read MoreIn 2013 Twitter published why their own front page had too much inline JavaScript for CSP. Today x.com forbids inline event handlers outright.
Read MoreMagecart targeted British Airways to gain access to significant quantities of PII and PCD, resulting in 8-figure fines for the organisation.
Read More