Scott Helme @scotthelme.bsky.social · 23/09/2026A bunch of these domains went from first registration to being flagged in our threat intel feed in just 30 hours! There's a massive IoC list at the end of the post 💪 161
Scott Helme @scotthelme.bsky.social · 22/09/2026It's pretty awesome to have this rolled out to 100% of users already!! 🤩 131
Scott Helme @scotthelme.bsky.social · 16/09/2026It's so cool when you see something you built working exactly as intended 😎 030
Scott Helme @scotthelme.bsky.social · 15/09/2026If you want a free @report-uri.bsky.social account during the beta, and then 50% off your first year as a thankyou, check out our new Magento CSP module in beta! 😎 010
Reposted by Scott HelmeJoe Tidy BBC News @joetidy.bsky.social · 07/09/2026Great bit of research here from @scotthelme.bsky.social who decided to put a hacking group's story to the test. The criminals who hacked the three UK airports boasted about how easy it was and Scott checked the receipts. Apparently it was EXTREMELY basic stuff: scotthelme.co.uk/no-hacking-r...scotthelme.co.ukNo Hacking Required: The Manchester Airports Group Data BreachOn 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and ... 284
Scott Helme @scotthelme.bsky.social · 07/09/2026They exposed data on 8.8 million people with no exploit, no malware, and no access to MAG’s servers. Three server-side API keys sat in public JavaScript for 4+ years and FulcrumSec found them. They could have modified and deleted data too. scotthelme.co.uk/no-hacking-r...scotthelme.co.ukNo Hacking Required: The Manchester Airports Group Data BreachOn 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and… 1154
Scott Helme @scotthelme.bsky.social · 06/09/2026OK, it's not brilliant and the setup needs some work, but I got my first real data down from the weather satellite this morning! It's a homemade antenna on the roof, into a £40 dongle and a raspberry pi. The satellite was METEOR-M2 3, 838 km overhead(!), on 137.9 MHz. 080
Scott Helme @scotthelme.bsky.social · 05/09/2026AOS!!! Weather satellite image download, first attempt. 137.9 MHz — Meteor-M N2-4 Dipole antenna @ 120°, aimed north Raspberry Pi 4B + £40 USB dongle Thirteen minutes as it passes 800 km overhead. No idea yet whether it'll work... 100
Scott Helme @scotthelme.bsky.social · 03/09/2026How can you possibly know your website is secure if you don’t know what code is actually running in your users’ browsers?! It seems like such a basic question, but most organisations simply can’t answer it. Now you can! 020
Reposted by Scott HelmeReport URI @report-uri.bsky.social · 01/09/2026🚀 Connection Allowlist is now in open beta at Report URI! Build an egress firewall directly into the browser: control where pages can connect, block unauthorised destinations and detect attempted data exfiltration. Learn more and try it now 👇 blog.report-uri.com/connection-a...blog.report-uri.comConnection Allowlist: an egress firewall for the browserUntil now, malicious code running in a browser has had several ways to send data somewhere it shouldn’t, including new channels that CSP cannot fully cover and channels that do not even appear in the ... 012
Scott Helme @scotthelme.bsky.social · 24/08/2026I recently completed a 1,600+ mile road trip around Europe, and these two bits of kit performed exceptionally well! 😎 scotthelme.co.uk/the-ultimate...scotthelme.co.ukThe ultimate road trip combo: Starlink Mini + UniFi Travel RouterI recently went on an epic road trip around Europe, covering 1,645 miles (2,647 km), and we took in some amazing sights and locations. As a tech geek, I was worried about my connectivity on the trip,… 110
Scott Helme @scotthelme.bsky.social · 21/08/2026I've just built and released a free tool: dbsc.dev Now you can check if your browser supports Device Bound Session Credentials! scotthelme.co.uk/introducing-...dbsc.devDoes your browser support DBSC?A live test of whether your browser supports Device Bound Session Credentials (DBSC), showing the whole protocol exchange: the registration JWT, your device key, and a real session refresh. 021
Scott Helme @scotthelme.bsky.social · 11/08/2026DBSC is now available in Chrome on macOS! 😎 It's currently rolling out in a Finch experiment and it looks like ~70% of people will have it already. scotthelme.co.uk/device-bound...scotthelme.co.ukDevice Bound Session Credentials lands in Chrome on macOSDevice Bound Session Credentials (DBSC) is Chrome's answer to session cookie theft, usually by InfoStealer malware. Instead of a cookie being a bearer token that works anywhere it's pasted, DBSC… 010
Scott Helme @scotthelme.bsky.social · 10/08/2026This is a bit of a 'stories from the trenches' post about building and deploying DBSC in a production app. If you're planning on taking DBSC for a spin, I'd recommend reading this first! scotthelme.co.uk/everything-i...scotthelme.co.ukEverything I Learned Shipping Device Bound Session CredentialsWe shipped Device Bound Session Credentials at Report URI, open-sourced the server-side implementation, and then discovered a long list of things the specification doesn't prepare you for. Some… 010
Reposted by Scott HelmeReport URI @report-uri.bsky.social · 28/07/2026Stripe just made CSP a compliance requirement. Merchants completing their annual PCI assessment are now asked to attest that they’ve deployed a Content Security Policy. That’s a major shift from “you should deploy CSP” to “confirm that you have.” Full details: blog.report-uri.com/stripe-now-a...blog.report-uri.comStripe Now Asks You to Attest That You've Deployed a CSPStripe's PCI assessment now has a mandatory checkbox: confirm you've deployed a Content Security Policy. Here's what you're attesting to, and how to do it. 011
Reposted by Scott HelmeReport URI @report-uri.bsky.social · 23/07/2026Onboarding just got a whole lot easier! 🤖 Using Claude, ChatGPT, Gemini, or another AI agent? Login, click "Copy Prompt", paste it into your AI, and it'll configure CSP reporting for you. Get up and running in minutes 😎 report-uri.com 011
Scott Helme @scotthelme.bsky.social · 22/07/2026I've just updated whynopasskeys.com 🌍🔑 Thanks for the community input updating the directory! 💪whynopasskeys.comWhy No Passkeys? — top sites without passkey support20 of the world's top 50 websites still don't support passkeys. See the global list and per-country reports. 032
Scott Helme @scotthelme.bsky.social · 20/07/2026We've released a new version of report-uri/dbsc-php thanks to community contributions! Full details: github.com/report-uri/d... Background: scotthelme.co.uk/open-sourcin...github.comReleases · report-uri/dbsc-phpContribute to report-uri/dbsc-php development by creating an account on GitHub. 021
Scott Helme @scotthelme.bsky.social · 08/07/2026This looks like it could be really promising! Connection Allowlist: a network firewall, built into the browser scotthelme.co.uk/connection-a...scotthelme.co.ukConnection Allowlist: a network firewall, built into the browserConnection Allowlist is a new browser security mechanism that lets a document declare, up front, the exact set of destinations it's permitted to open network connections to. Anything not on the list… 092
Scott Helme @scotthelme.bsky.social · 07/07/2026It hasn't changed in over a decade, so I've just given my captive portal buster a new look! 😎 httpforever.comhttpforever.comHTTP Forever — A reliably insecure connectionA plain-HTTP page that helps you trigger captive portal login screens on public WiFi — on trains, in hotels, bars and on flights. 221
Scott Helme @scotthelme.bsky.social · 04/07/2026Are there any other special TLDs that you’d like to see called out specifically? whynopasskeys.com#tldswhynopasskeys.comWhy No Passkeys? — top sites without passkey support18 of the world's top 50 websites still don't support passkeys. See the global list and per-country reports. 020
Scott Helme @scotthelme.bsky.social · 03/07/2026Do we think these AI companies should have used AI to build passkey support into their sites? 🤖🔑 whynopasskeys.com/tld/aiwhynopasskeys.comWhy No Passkeys? — .ai sites47 of the top 50 .ai websites don't support passkeys. 130
Scott Helme @scotthelme.bsky.social · 03/07/2026I’ve just pushed an update to whynopasskeys.com It now covers the global top 50 sites and the top 50 for every country!whynopasskeys.comWhy No Passkeys? — top sites without passkey support18 of the world's top 50 websites still don't support passkeys. See the global list and per-country reports. 220
Scott Helme @scotthelme.bsky.social · 01/07/202610 years ago, I started analysing the security of the Top 1 Million websites. Here’s the state of web cryptography after a decade of observation! scotthelme.co.uk/top-1-millio...scotthelme.co.ukTop 1 Million Analysis – June 2026: The State of CryptoThis is part two of the ten-year anniversary Top 1 Million Analysis. Part one covered the broad state of the web — HTTPS, the security headers, cookies, email and DNS hygiene. This part is the bit I'v... 020
Reposted by Scott HelmeTroy Hunt @troyhunt.com · 30/06/2026Weekly update is up! Live From Mallorca with @scotthelme.bsky.social - We’re talking passkeys and Claude Code: www.troyhunt.com/weekly-updat...troyhunt.comWeekly Update 510: Live From Mallorca with Scott HelmeHow's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport... 032
Scott Helme @scotthelme.bsky.social · 29/06/2026I can't believe it's been 10 years since I started my crawler project and analysed the security of the Top 1 Million sites!! scotthelme.co.uk/top-1-millio...scotthelme.co.ukTop 1 Million Analysis – June 2026: Ten Years of Web SecurityIt's been a long time since the last one of these! The previous Top 1 Million Analysis was way back in June 2022, and a lot has happened since then. But there's a much bigger reason to dust off the cr... 020
Scott Helme @scotthelme.bsky.social · 24/06/2026Someone re-registered a former MaxCDN asset domain that thousands of websites still reference. They now control wildcard DNS across the old WP Engine namespace. It isn’t exploitable today—but that could change at the drop of a hat... scotthelme.co.uk/a-dead-cdn-a...scotthelme.co.ukA dead CDN, a wildcard, and an attack waiting to happen: the netdna-ssl.com takeoverEvery now and then I go digging through Report URI's Threat Intelligence data feeds, looking for domains that show up in CSP reports where they really shouldn't. Last week one jumped out at me: netdna... 001
Scott Helme @scotthelme.bsky.social · 23/06/2026Thanks for all the feedback, I've made some changes and just deployed new data 🔑 whynopasskeys.comwhynopasskeys.comWhy No Passkeys? — top sites without passkey support6 of the world's top 25 websites still don't support passkeys. See the global list and per-country reports. 010
Scott Helme @scotthelme.bsky.social · 22/06/20267 of the world’s top 25 websites still don’t support passkeys. Why No Passkeys? tracks adoption across the biggest sites globally—and highlights who’s still missing out. whynopasskeys.comwhynopasskeys.comWhy No Passkeys? — top sites without passkey support7 of the world's top 25 websites still don't support passkeys. See the global list and per-country reports. 144
Scott Helme @scotthelme.bsky.social · 15/06/2026A single support ticket XSS became the front door to 275 million student records! scotthelme.co.uk/the-instruct...scotthelme.co.ukThe Instructure Canvas Breach (2026): How XSS in a Support Ticket Compromised 275 Million StudentsA single support ticket became the front door to 275 million student records. The Canvas breach shows how quickly untrusted user content can become a serious security incident when it is rendered insi... 030
Scott Helme @scotthelme.bsky.social · 02/06/2026Cookies are still one of the weakest links in Web security! Device Bound Session Credentials could change that. scotthelme.co.uk/device-bound...scotthelme.co.ukDevice Bound Session Credentials: Making Stolen Cookies UselessA stolen session cookie can be vastly more powerful than a stolen password. The attacker doesn’t need to phish the user, bypass MFA, or defeat their passkey; they simply replay the cookie and step str... 040
Scott Helme @scotthelme.bsky.social · 21/05/2026Passkeys are supposed to be browser-enforced security. But what happens when a browser extension can step into the WebAuthn flow and bypass the rules your site explicitly set? I dug into 1Password, Permissions Policy, and a questionable edge case: scotthelme.co.uk/passkeys-per...scotthelme.co.ukPasskeys, Permissions Policy and Bug Hunting in 1Password's WebAuthn WrapperPasskeys are the best thing to happen to web authentication in years, but a passkey ceremony is only as secure as the stack enforcing it. The browser, the relying party, the authenticator, and any ext... 030
Scott Helme @scotthelme.bsky.social · 20/05/2026Another piece of work this week to boost the adoption of passkeys online! We've open-sourced our WebAuthn server lib that we use at @report-uri.bsky.social in production 😎 062
Scott Helme @scotthelme.bsky.social · 19/05/2026I fell down the rabbit hole on this one, and there are more blog posts coming this week and next on the research! XSS is always bad, but I didn't quite realise how bad. 062
Scott Helme @scotthelme.bsky.social · 18/05/2026We have some pretty cool research coming out this week, here's the groundwork before we get started! 😎 031
Scott Helme @scotthelme.bsky.social · 15/05/2026This was another piece of particularly crafty malware! Imagine having the level of access that the attackers had here, and then choosing to inject a JS keylogger. Sounds crazy, but there's a good reason for it. 020
Scott Helme @scotthelme.bsky.social · 07/05/2026It's really quite awesome to see some of the new features and capabilities we're adding right now. 😎 Exciting times ahead! 💪 020
Scott Helme @scotthelme.bsky.social · 22/04/2026Kind of crazy that after all the progress we’ve made with passwords, 2FA, and now passkeys, the end result is still just… a cookie! Attackers will follow the value and the path of least resistance, meaning shifting to abusing the authenticated session. Check out my blog post and new white paper! 131
Scott Helme @scotthelme.bsky.social · 18/04/2026Is it a bird, is it a…. Wait, yes that’s a bird 🤣 (zoom in) 070
Scott Helme @scotthelme.bsky.social · 13/04/2026This is quite an interesting piece of ongoing work! 030
Scott Helme @scotthelme.bsky.social · 07/04/2026We've since found a few more extensions and flagged them with Google/Microsoft! 😎 Does anyone know how we can get these extensions taken down faster? They're still active! 011
Reposted by Scott HelmeReport URI @report-uri.bsky.social · 02/04/2026Our founder has just published a write-up on having our Passkeys implementation independently security tested. Auth is too important to just ship and hope for the best, so we brought in the experts! scotthelme.co.uk/bringing-in-...scotthelme.co.ukBringing in the experts; Having our Passkeys implementation Security TestedWe recently announced support for Passkeys on your Report URI account, and everyone should go and enable Passkeys for the amazing security benefits they offer. As a new implementation of an authentica... 011
Scott Helme @scotthelme.bsky.social · 30/03/2026Our March update was a big one! 😎 🤖 API and MCP Endpoints 🔑 Passkeys support 📈 Report Sampling 🛡️ Integrity Suite 📋 Audit Trail 👀 Visual updates And loads more! blog.report-uri.com/newsletter-m...blog.report-uri.comNewsletter - Mar 2026Both January and February were big months for us at Report URI HQ, and we have continued to push forwards in March! API and MCP endpoints - beta invites! 🤖 Starting out with what has to be our mos... 031
Scott Helme @scotthelme.bsky.social · 27/03/2026I'm not one for hyperbole, but watching our first few customers get hands on with MCP access has shown just how transformational this will be! 😎 000
Scott Helme @scotthelme.bsky.social · 24/03/2026I love getting stuck in to some proper technical work! 😎 020
Reposted by Scott HelmeReport URI @report-uri.bsky.social · 18/03/2026We're starting to see some really positive results with more customers using our CSP Integrity feature! scotthelme.co.uk/leverage-our...scotthelme.co.ukLeverage our treasure trove of Threat Intelligence dataWe've been working on CSP Integrity for a little while now, and it was only announced in open beta back in September. Since then, as more of our customers start to use it, we've continued to improve i... 021
Scott Helme @scotthelme.bsky.social · 17/03/2026The new reduced limit of 200 days validity for certificates landed over the weekend and, so far, all seems good! scotthelme.co.uk/shorter-cert...scotthelme.co.ukShorter certificates are coming!Well, I was certainly hoping for this result, but wasn't necessarily expecting it! I'm pleased to report that Ballot SC-081v3 passed, and that shorter certificate lifetimes are now coming! The Sche... 040