Sign in

Report URI

@report-uri.bsky.social
19 followers 1 following 32 posts

We're the market leader in browser security technologies, enabling you to detect and mitigate attacks, fast.

PostsRepliesMedia
Report URI @report-uri.bsky.social · 23/09/2026
One suspicious domain led us to 2,000+ compromised WordPress sites, a fake reCAPTCHA lure and a macOS infostealer targeting crypto wallets, browser cookies and Keychain data. We traced the campaign to sanctioned Russian infrastructure and published the IOCs: blog.report-uri.com/chasing-a-cl...
blog.report-uri.com
Chasing a ClickFix Campaign From One Domain to a macOS Stealer
Yesterday, we traced a single domain from an external threat feed through an extensive delivery chain: compromised WordPress sites, a fake reCAPTCHA challenge and a macOS cryptocurrency stealer delive...
010
Report URI @report-uri.bsky.social · 22/09/2026
We’ve rolled out Device Bound Session Credentials to 100% of Report URI logins. 🔐 67.7% of our active sessions are already device-bound, making this what we believe to be one of the first production DBSC deployments outside Google. Here’s how we did it: blog.report-uri.com/we-rolled-ou...
blog.report-uri.com
We rolled out Device Bound Session Credentials to every Report URI login
Since 1st September 2026, every single login to Report URI has been offered a Device Bound Session Credential. That's 100% of our users, on the live site, all day, every day. As far as we can tell, t...
021
Report URI @report-uri.bsky.social · 16/09/2026
We deployed an update at 14:00 UTC that introduced a new JavaScript dependency. At 14:04 UTC, Script Watch alerted us to it. That is the visibility you need in the browser: know when new code appears on your site, whether the change is expected or not. Four minutes from deployment to detection! ⏱️
010
Report URI @report-uri.bsky.social · 15/09/2026
Magento has shipped with CSP enabled by default since 2.3.5, but most stores never configure a reporting endpoint. We found 2,236 Magento sites taking card payments with this exact gap, so we built a free module to fix it: blog.report-uri.com/magento-alre...
blog.report-uri.com
Magento already ships CSP: start monitoring it today
Magento 2 has shipped with Content Security Policy enabled by default since version 2.3.5. On current releases, most pages use a report-only policy, while payment pages use an enforced policy by defau...
020
Report URI @report-uri.bsky.social · 04/09/2026
Our logo's in good company this weekend. 🏁 Will Orton & Jessica Hawkins go into Donington Park leading British GT4! 😎 Proud to back the #21 Aston Martin with MKH Racing. #BritishGT #GT4
020
Report URI @report-uri.bsky.social · 03/09/2026
Do you know exactly what JavaScript ran in your users’ browsers? We fingerprint every executed script, alert when something changes and preserve a verified copy for investigation. Zero code on your page. blog.report-uri.com/we-can-prove...
blog.report-uri.com
We can prove exactly what JavaScript ran in your users’ browsers
Right now, on our own production site, I can tell you the cryptographic fingerprint of every single JavaScript file that executed in a real visitor's browser this month. Not what our build system prod...
010
Report URI @report-uri.bsky.social · 01/09/2026
🚀 Connection Allowlist is now in open beta at Report URI! Build an egress firewall directly into the browser: control where pages can connect, block unauthorised destinations and detect attempted data exfiltration. Learn more and try it now 👇 blog.report-uri.com/connection-a...
blog.report-uri.com
Connection Allowlist: an egress firewall for the browser
Until now, malicious code running in a browser has had several ways to send data somewhere it shouldn’t, including new channels that CSP cannot fully cover and channels that do not even appear in the ...
012
Report URI @report-uri.bsky.social · 04/08/2026
ClickFix tricks users into compromising their own machines and hides its payload on a blockchain. But the attack still begins the same way: a website runs JavaScript it was never meant to run. That’s where we could have stopped it. blog.report-uri.com/the-clickfix...
blog.report-uri.com
The ClickFix Attack We Could Have Stopped
A customer forwarded us something last week that has stuck with me. It was a live attack campaign — a good one, in the professional-admiration sense — along with a detailed public write-up dissecting ...
000
Report URI @report-uri.bsky.social · 28/07/2026
Stripe just made CSP a compliance requirement. Merchants completing their annual PCI assessment are now asked to attest that they’ve deployed a Content Security Policy. That’s a major shift from “you should deploy CSP” to “confirm that you have.” Full details: blog.report-uri.com/stripe-now-a...
blog.report-uri.com
Stripe Now Asks You to Attest That You've Deployed a CSP
Stripe's PCI assessment now has a mandatory checkbox: confirm you've deployed a Content Security Policy. Here's what you're attesting to, and how to do it.
011
Report URI @report-uri.bsky.social · 23/07/2026
Onboarding just got a whole lot easier! 🤖 Using Claude, ChatGPT, Gemini, or another AI agent? Login, click "Copy Prompt", paste it into your AI, and it'll configure CSP reporting for you. Get up and running in minutes 😎 report-uri.com
011
Reposted by Report URI
Scott Helme @scotthelme.bsky.social · 20/07/2026
We've released a new version of report-uri/dbsc-php thanks to community contributions! Full details: github.com/report-uri/d... Background: scotthelme.co.uk/open-sourcin...
github.com
Releases · report-uri/dbsc-php
Contribute to report-uri/dbsc-php development by creating an account on GitHub.
021
Report URI @report-uri.bsky.social · 20/05/2026
We’ve open-sourced passkeys-php, the WebAuthn library we use at Report URI, to help the community deploy passkeys more easily and safely. Small. Auditable. MIT licensed. Built for real-world PHP apps. Our founder, @scotthelme.bsky.social, shared the details today: scotthelme.co.uk/open-sourcin...
scotthelme.co.uk
Open-Sourcing passkeys-php: A Security-Focused WebAuthn Library for PHP
We've open-sourced passkeys-php, the WebAuthn server library we use at Report URI to protect logins with passkeys, security keys, and platform authenticators like Touch ID, Face ID, and Windows Hello....
062
Report URI @report-uri.bsky.social · 19/05/2026
Great research from our founder, @scotthelme.bsky.social, on one of the hidden risks of passkeys. Passkeys reduce phishing risk, but malicious JavaScript in the browser can abuse registration and create persistent account takeovers! Client-side visibility matters. scotthelme.co.uk/xss-is-deadl...
scotthelme.co.uk
XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
A single XSS vulnerability can turn passkeys from a phishing-resistant login mechanism into a persistent account takeover backdoor. If malicious JavaScript can run on your page, it may be able to regi...
012
Report URI @report-uri.bsky.social · 18/05/2026
Passkeys are becoming a major part of how we secure accounts online, but there’s still confusion about how they work, and what risks remain. Our founder, @scotthelme.bsky.social, has written an intro to Passkeys before we publish deeper technical posts this week. scotthelme.co.uk/passkeys-101...
scotthelme.co.uk
Passkeys 101: An Introduction to Passkeys and How They Work
Passwords have been the weak point in online authentication for decades. They can be reused, guessed, stolen, phished, leaked, sprayed, stuffed, and captured by malware. Passkeys are one of the first ...
010
Report URI @report-uri.bsky.social · 15/05/2026
A checkout page can look secure, work normally, and still be stealing customer payment data. @scotthelme.bsky.social breaks down a real-world JS compromise where attackers skimmed card data from the page, and why orgs need visibility into the code they're running. scotthelme.co.uk/anatomy-of-a...
scotthelme.co.uk
Anatomy of a WooCommerce Skimmer: A Technical Deep-Dive
One malicious change to a trusted JavaScript file can turn your checkout page into a silent credit-card skimmer, siphoning customer data off to criminals while the website looks secure and continues t...
010
Report URI @report-uri.bsky.social · 07/05/2026
Q2 is off to a busy start at Report URI 🚀 🔹 API/MCP endpoints GA 🔹 Audit Trail to Webhook 🔹 Custom Fingerprints for JS 🔹 Audit Archive for JS 🔹 Reporting API in @firefox.com 🔹 Deeper CSP inspection 🔹 Passkeys research + whitepaper 🔹 New Threat Intel research blog.report-uri.com/newsletter-a...
blog.report-uri.com
Newsletter - Apr 2026
As we continue to push into 2026, we’ve maintained our pace of improving existing features and introducing new ones. API and MCP endpoints - now Generally Available 🤖 Our API and MCP endpoints are...
010
Report URI @report-uri.bsky.social · 22/04/2026
The NCSC is right to push passkeys. They’re a huge step forward for authentication: phishing-resistant, no shared secret on the server, far better than passwords in many ways. But passkeys don’t make your application trustworthy after login!
100
Report URI @report-uri.bsky.social · 22/04/2026
Good morning Glasgow! 🏴󠁧󠁢󠁳󠁣󠁴󠁿 Come and find us at CyberUK booth G13 and see how we can show you exactly what code is running on your website. 👨‍💻 #CYBERUK26
020
Report URI @report-uri.bsky.social · 20/04/2026
The Report URI refresh is live! 💙🧡 New homepage, refreshed product + case study pages, all-new social cards across the site, and more. Same mission: catching the third-party code your website is running that you don't control. ➡️ report-uri.com
report-uri.com
Client-Side Security and Observability.
Protect user data and prevent client-side data breaches with real-time browser security controls.
010
Report URI @report-uri.bsky.social · 13/04/2026
We're tracking an active Magecart campaign targeting ecommerce sites. The malware hides from admins, adapts to the platform, and changes how it steals payment data! Write-up: scotthelme.co.uk/fighting-an-...
scotthelme.co.uk
Fighting an active Magecart Campaign
We’ve been tracking an active Magecart campaign targeting ecommerce sites, with payloads customised per victim and evasion logic designed to stay hidden from site owners. We spotted it because we moni...
120
Report URI @report-uri.bsky.social · 07/04/2026
We uncovered a malicious browser extension injecting JavaScript Malware into pages, hijacking clicks, and monetising user traffic right inside the browser! scotthelme.co.uk/amazing-refr...
scotthelme.co.uk
Amazing Refresh — A Malicious Chrome Extension Running Malware in the Browser
We recently uncovered a malicious browser extension affecting visitors to customer websites. It injected JavaScript into pages, hijacked outbound clicks through affiliate infrastructure, and quietly m...
000
Report URI @report-uri.bsky.social · 02/04/2026
Our founder has just published a write-up on having our Passkeys implementation independently security tested. Auth is too important to just ship and hope for the best, so we brought in the experts! scotthelme.co.uk/bringing-in-...
scotthelme.co.uk
Bringing in the experts; Having our Passkeys implementation Security Tested
We recently announced support for Passkeys on your Report URI account, and everyone should go and enable Passkeys for the amazing security benefits they offer. As a new implementation of an authentica...
011
Reposted by Report URI
Scott Helme @scotthelme.bsky.social · 30/03/2026
Our March update was a big one! 😎 🤖 API and MCP Endpoints 🔑 Passkeys support 📈 Report Sampling 🛡️ Integrity Suite 📋 Audit Trail 👀 Visual updates And loads more! blog.report-uri.com/newsletter-m...
blog.report-uri.com
Newsletter - Mar 2026
Both January and February were big months for us at Report URI HQ, and we have continued to push forwards in March! API and MCP endpoints - beta invites! 🤖 Starting out with what has to be our mos...
031
Report URI @report-uri.bsky.social · 27/03/2026
We’re inviting customers to join the beta for our new API and MCP integrations. Bring Report URI data into AI assistants, automations, dashboards, and custom security tooling. Want in? Details in our newsletter: blog.report-uri.com/newsletter-m...
blog.report-uri.com
Newsletter - Mar 2026
Both January and February were big months for us at Report URI HQ, and we have continued to push forwards in March!
010
Report URI @report-uri.bsky.social · 24/03/2026
At the scale we operate at, “one in a billion” problems can happen every single day! In our latest blog post, we share some of the challenges that come with operating Redis at scale, and what it takes to keep a high-volume telemetry pipeline fast and resilient. scotthelme.co.uk/when-one-in-...
scotthelme.co.uk
When “One in a Billion” Happens Every Day: Scaling Redis at Report URI
Something that I've come to learn as we continue to grow Report URI is that everything is easy until scale makes it hard. We're now processing so much telemetry that a "one in a billion" problem can h...
011
Report URI @report-uri.bsky.social · 18/03/2026
We're starting to see some really positive results with more customers using our CSP Integrity feature! scotthelme.co.uk/leverage-our...
scotthelme.co.uk
Leverage our treasure trove of Threat Intelligence data
We've been working on CSP Integrity for a little while now, and it was only announced in open beta back in September. Since then, as more of our customers start to use it, we've continued to improve i...
021
Report URI @report-uri.bsky.social · 05/03/2026
Today is your last chance to catch us at @ndcconferences.com Security in Oslo! We’ve had a great week of workshops, talks and conversations at the booth. Stop by for a chat with our founder @scotthelme.bsky.social about his talk “Your website is running code you’ve never seen!”
022
Report URI @report-uri.bsky.social · 27/02/2026
Big update from Report URI 🚀 ✅ Report Sampling in Open Beta ✅ Audit Trail in Open Beta ✅ Alert thresholds for all Watch products ✅ New Magecart case study ✅ CSP Integrity webinar recording live ✅ Find us at NDC Security Oslo 4–5 Mar, CyberUK Glasgow 21–23 Apr blog.report-uri.com/newsletter-f...
blog.report-uri.com
Newsletter - Feb 2026
After kicking 2026 off with a pretty big update, we've continued to push forwards with a lot of work across the board at Report URI HQ.
021
Report URI @report-uri.bsky.social · 02/02/2026
A recent security incident at a space agency highlighted a growing and often misunderstood risk: modern websites increasingly depend on third-party JavaScript, and that code runs with the same privileges as your own. report-uri.com/case_studies...
report-uri.com
Case Study - European Space Agency
The European Space Agency was hit by a Magecart attack during Christmas 2024, and we could have stopped it
010
Report URI @report-uri.bsky.social · 28/01/2026
Eating Our Own Dogfood: What Running Report URI on Report URI Taught Us scotthelme.co.uk/eating-our-o...
scotthelme.co.uk
Eating Our Own Dogfood: What Running Report URI on Report URI Taught Us
Dogfooding is often talked about as a best practice, but I don't often see the results of such activities. For all new features introduced on Report URI, we are always the first to try them out and se...
011
Report URI @report-uri.bsky.social · 18/12/2025
As is tradition, we've completed our annual penetration test and the results have been published publicly for all to see! Curious what was found, what we've done to resolve issues, or what a penetration test report looks like? Come and have a read! scotthelme.co.uk/report-uri-p...
scotthelme.co.uk
Report URI Penetration Test 2025
Every year, just as we start to put up the Christmas Tree, we have another tradition at Report URI which is to conduct our annual penetration test! 🎅🎄🎁 --> 🩻🔐🥷 This will be our 6th annual penetratio...
031
Report URI @report-uri.bsky.social · 09/12/2025
We’re ready for @blackhatevents.bsky.social EU! Are you? 😎 #BHEU
011
Report URI @report-uri.bsky.social · 19/11/2025
Do you want to quickly and easily know if all of your JavaScript assets across your site are using SRI? Now you can! Announcing the open-beta of Integrity Policy! scotthelme.co.uk/integrity-po...
scotthelme.co.uk
Integrity Policy - Monitoring and Enforcing the use of SRI
This has been a long time coming so I'm excited that we now have a working standard in the browser for monitoring and enforcing the use of SRI across your website assets! SRI refresher For those...
031