ZeroHour

Source: Troy Hunt

1,023 stories

Weekly Update 521: Breach Perception v. Reality

Troy Hunt's weekly update argues AI's hacking role is overstated, citing exposed keys and human error behind recent breach headlines.

Troy Hunt's Weekly Update 521 argues that media coverage exaggerates AI as a hacking tool. He cites data showing AI has had roughly 0% impact on cyber insurance payouts, a MAG breach teardown attributing the incident to exposed keys rather than sophistication, and a Dutch suspect being tracked via his voice. He also notes an Australian headline claiming ChatGPT hacked a court system was actually a man who used ChatGPT to write a web scraper pointed at a website.

Troy Hunt · 4d agoIndustry

Troy Hunt

Troy Hunt warns ShinyHunters' Carhartt breach claim of 50GB and millions of records is unverified, while Sri Lanka joins Have I Been Pwned.

Troy Hunt's blog roundup centers on a cautionary tale about data breach claims: ShinyHunters claims it compromised Carhartt and stole over 50GB of compressed data containing millions of customer records, employee information and loyalty data, but Hunt stresses criminal claims require verification. The feed also covers Sri Lanka CERT becoming the 48th government onboarded to Have I Been Pwned's free government monitoring service, following Nepal as the 47th. Other commentary addresses ransomware economics, Brinks Home's lawyer-heavy extortion FAQ, and the Origin Energy breach in Australia.

Troy Hunt · 8d agoData breach

Weekly Update 519: Breaches & Data Integrity

Troy Hunt's weekly update mentions new breach data dumps, IoT door lock research, and conference preparations.

Troy Hunt's Weekly Update 519 notes that attackers have again dumped more stolen data, and discusses ongoing work including IoT door lock testing and mapping network hardware in Ubiquiti's design tool. It also references upcoming talks in Oslo and Copenhagen. The post is a routine personal update with no new vulnerability, breach details, or research findings.

Troy Hunt · 13d agoIndustry

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

Troy Hunt cautions that claimed Carhartt breach data requires verification, warning that criminals' breach claims are not always accurate.

Troy Hunt published a cautionary tale about data breach claims, verification, and apparel brand Carhartt. He argues that claimed breaches from cybercriminals should not be taken at face value and may stem from errors by the criminals themselves. The piece underscores the need to verify breach data before treating it as authentic, in the vein of Have I Been Pwned's validation practices.

Troy Hunt · 20d agoData breach

Welcoming the Sri Lankan Government to Have I Been Pwned

Have I Been Pwned onboarded Sri Lanka as the 48th government in its free service, letting Sri Lanka CERT monitor domains for breached accounts.

Have I Been Pwned added the Sri Lankan government as the 48th government onboarded to its free gov service. Sri Lanka CERT now has access to monitor Sri Lankan government domains against HIBP breach data, helping identify exposed government accounts and respond when they appear in new breaches.

Troy Hunt · 23d agoIndustry

Weekly Update 517: Cyber Ransoms

Troy Hunt's weekly commentary argues much ransomware is simple extortion by young actors who struggle to monetize ransoms.

In Weekly Update 517, Troy Hunt comments on the current ransomware landscape, noting many attacks involve pure extortion rather than actual malware. He observes that many actors are young and earn large sums but face practical difficulties spending ransom proceeds. The piece is opinion commentary rather than a new incident disclosure.

Troy Hunt · 28d agoIndustry

Weekly Update 516: Live From Vietnam

Troy Hunt's weekly video update, broadcast live from Vietnam, critiques Brinks Home's security FAQ.

Troy Hunt published episode 516 of his weekly video update, recorded from Vietnam. He highlights the Brinks Home security FAQ as the most interesting item of the week, questioning how the company wrote its own FAQ and then apparently failed to follow it. The truncated text provides no further technical details.

Troy Hunt · Aug 12, 2026Industry