Weekly Update 522: Live From Oslo with Scott Helme
Troy Hunt and Scott Helme discuss detecting malware-infected machines via CSP reporting and a surge of malicious browser extensions found with a local LLM.
Weekly Update 522, recorded live in Oslo with Scott Helme, covers how Report URI uses Content Security Policy reporting to identify malware-infected machines inside organizations. Helme also describes catching malicious browser extensions at a high rate using 'Rory', his local OpenClaw LLM instance.
- CSP report-uri data reveals malware-infected endpoints within organizations.
- Local OpenClaw LLM flags high volumes of malicious browser extensions.
Full article97 words · extracted from troyhunt.com · click to collapse
Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving - sorry! But get through that and have a listen to Scott's experiences with how Report URI is identifying malware-infected machines within orgs, all due to CSP reporting. It's a super cool use of the technology, and I'm sure there's an awesome potential for it that neither of us has really thought about yet. Plus, the crazy rate of malicious browser extensions he's picking up with help from "Rory", his local OpenClaw instance.
Weekly updateText extracted automatically; images, tables and formatting may be missing. Original: https://www.troyhunt.com/weekly-update-522/