MoreRSS

site iconTroy HuntModify

Create courses for Pluralsight and am a Microsoft Regional Director and MVP who travels the world speaking at events and training technology professionals.
Please copy the RSS to your reader, or quickly subscribe to:

Inoreader Feedly Follow Feedbin Local Reader

Rss preview of Blog of Troy Hunt

Welcoming the Nepalese Government to Have I Been Pwned

2026-08-03 14:38:05

Welcoming the Nepalese Government to Have I Been Pwned

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and respond quickly when those accounts appear in a new data breach.

This is precisely what the HIBP government service was built for: helping national cyber teams strengthen threat monitoring and incident response capabilities by providing visibility into compromised credentials and breached accounts across their government domain space.

Nepal joins a growing list of governments and national cybersecurity teams using HIBP to better understand their exposure, protect government departments and public resources, and reduce the risk posed by compromised credentials before attackers can take advantage.

Weekly Update 515

2026-08-03 08:07:14

Weekly Update 515

Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time in a lot of Italy, no, it's just not the same. It's not the same ubiquity of high-quality coffee shops and passion for what many view as the art of making espresso-based drinks. There's comparably little tolerance for the likes of Starbucks (who have not fared well in Australia), and other mass-produced forms of the drink (I don't think I've ever seen diner-style filter coffee here). All that said, we may have gone just a little overboard with the new machine, but anything worth doing is worth doing to excess 😊

Weekly Update 515
Weekly Update 515
Weekly Update 515
Weekly Update 515

Weekly Update 514: This Week in Data Breaches

2026-07-26 17:14:51

Weekly Update 514: This Week in Data Breaches

The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn't respond when I tried to report it", and now news that the two parties have "come to an agreement". Maybe money was paid, or maybe Origin made some promises to restrain the hounds if commitments about data deletion were made. But both outcomes, of course, provide no guarantee that data has been nuked, so now they get to spend perpetuity waiting for the data that maybe - just maybe - it leaks. And we all should be working on precisely that assumption, just like we did with Optus and Medibank and Latitude and Ticketek and Qantas...

Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches

References

  1. Sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free.

Weekly Update 513: Clauding The Home Network

2026-07-21 15:30:24

Weekly Update 513: Clauding The Home Network

I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's taking lots of noise and converting it into a useful signal. Or, sometimes, it's just helping you see the woods through the trees, and that's exactly what Claude helped me do last night when every Sonos unit in the house refused to connect to any music service. It only took Claude a moment to work out: "you know your Pi-Hole is dead, right?" Uh... I do now! Give it a go, it's pretty awesome (and the Pi-Hole came good with a power cycle on the PoE port).

Weekly Update 513: Clauding The Home Network
Weekly Update 513: Clauding The Home Network
Weekly Update 513: Clauding The Home Network
Weekly Update 513: Clauding The Home Network

Weekly Update 512: IoT Lockout Fail

2026-07-15 08:35:38

Weekly Update 512: IoT Lockout Fail

"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the 9V "jump start" procedure completely failing! Eventually, the locksmith arrived and opened an old-school physical lock on another door in an alarmingly short time. So, lessons:

  1. Battery-powered locks suck and will eventually lock you out of your house
  2. Don't trust a fallback mechanism as rudimentary as "hold a 9V battery on some terminals"
  3. Always have an old school manual backup approach, AKA "a key"

As I say in the video, we do have other doors that have keys, and if it weren't for the complacency we developed, we would have had one of these accessible. But alas, we didn't. The path forward is to take a deep dive into Ubiquiti's Access ecosystem, which I've flagged in the past, and by pure coincidence, I already had a meeting lined up with them to discuss just this. So, the hardware is on the way, and I'll have something entirely new to play with in the coming weeks. Stay tuned!

Weekly Update 512: IoT Lockout Fail
Weekly Update 512: IoT Lockout Fail
Weekly Update 512: IoT Lockout Fail
Weekly Update 512: IoT Lockout Fail

Weekly Update 511: Live from my Riad in Marrakech

2026-07-08 21:54:46

Weekly Update 511: Live from my Riad in Marrakech

How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with various companies wanting to place that message alongside the very data breaches they can do nothing about! As I say in the post, I don't question the good intentions behind setting up a service to try to scrub data from legally operating data brokers, but the marketing machines behind those organisations that regularly reach out to me for product placement don't really seem to grasp that reality. At least now they have a nice explainer courtesy of that post 😊

Weekly Update 511: Live from my Riad in Marrakech
Weekly Update 511: Live from my Riad in Marrakech
Weekly Update 511: Live from my Riad in Marrakech
Weekly Update 511: Live from my Riad in Marrakech