Articles
- Okta 2023: how HAR files in a support system became hijacked admin sessions
A support-system password saved in a personal Chrome profile let an attacker read customer support files at Okta for three weeks. Some were HAR files holding live session cookies, which were replayed against 1Password, BeyondTrust and Cloudflare. Step by step, why logging missed it, and the controls that break each step.
- Alternative to Cloudflare Access for public sites: passwordless sign-in with osec Auth and Login Protection
Cloudflare Access is free for up to 50 users and puts a login in front of your apps. Five reasons a small site with its own sign-in can use osec Auth and Login Protection instead: no proxy, no OAuth setup, email codes, Google and Apple. Includes pricing and where Cloudflare Access is the better choice.
- Alternative to Cloudflare Bot Management: osec Bot Gate and Fingerprint Lite for small sites
Cloudflare's bot protection starts free with Bot Fight Mode, then $20 and $200 a month, or a sales quote. Five reasons a small site can use osec Bot Gate, Fingerprint Lite and Captcha instead, with a proxy-free setup, pricing and where Cloudflare is the better choice.
- Alternative to Cloudflare Turnstile: five reasons to use osec Captcha instead, and when not to
Turnstile is free with no request cap, so it's the default choice for most small sites. Five reasons to use osec Captcha, Signup Checks and Bot Gate instead: no Cloudflare account, a check you run yourself, and a free tier of 500 a day. Includes pricing and where Turnstile is better.
- Alternative to reCAPTCHA: five reasons a small site can switch, and what it costs
reCAPTCHA's free tier is 10,000 assessments a month, then billing starts. Five reasons to try osec Captcha, Login Protection and Signup Checks instead, with pricing at each level and where reCAPTCHA is still the better choice.
- Fingerprint Pro vs osec Fingerprint Lite: what visitor identification costs, and what you give up
Fingerprint Pro costs $99 a month for 20,000 identifications, then $4 per 1,000. osec Fingerprint Lite gives 500 a day free and charges by capacity. Here's the price at each volume, and where Lite is weaker.
- An nginx hardening checklist: timeouts, body limits and a check script
Slow clients, oversized bodies and version banners are cheap to fix in nginx. Set the limits once, then run a bash script that checks them from outside, so drift shows up.
- Block whole networks cheaply with ipset and a bash script
One firewall rule per address doesn't scale. ipset keeps thousands of addresses and ranges in one hash set, so a single iptables rule drops all of them at a fast lookup.
- Security patches on their own: unattended-upgrades on Ubuntu
Most breaches ride on bugs that already have a patch. unattended-upgrades installs security updates each day, leaves reboots to you, and writes a log you can check with a short script.
- Close probe paths and bad user agents in nginx with return 444
Most bot traffic asks for the same few paths. nginx can close those connections with the non-standard code 444 before your app wakes up, with no response for the scanner to read.
- A Python report of bot pings, from your own nginx access log
Before you write a single rule, measure. This script reads the nginx access log, groups requests by IP, counts probes, and prints the top offenders you can ban or rate limit.
- fail2ban for SSH, then a recidive jail for repeat offenders
A ten-minute ban just makes a bot wait. The recidive jail reads fail2ban's own log and bans repeat offenders for a week, across every jail.
- A default-deny firewall for a small server with ufw
Open only the ports you serve, rate-limit SSH, and keep the rules in a script you can rerun. ufw covers it in about twenty lines, with a rollback path.
- SSH hardening: keys only, one allowed user, and a way back in
Password guessing against port 22 is constant background noise. Turn off password logins, limit who can log in, and test from a second session before you close the first.
- nginx rate limiting that slows bots without locking out people
limit_req counts requests per key over time. Set it per IP for login and API paths, allow short bursts for real browsers, and return 429 so you can see what happened.
- fail2ban for nginx: ban the bots that keep knocking on /.env and /wp-login.php
Scanners request /wp-login.php, /.env and /phpmyadmin hundreds of times a day. fail2ban reads your nginx logs and bans the IPs that do it, with two jails you can test in five minutes.
- Sign-in rules that count emails and wrong codes, not just IPs
Credential stuffing and code-bombing hit sign-in pages first. A generic rate limit counts per IP over seconds; attackers rotate IPs over hours. osec Login Protection adds per-email and per-IP code limits per hour, wrong-code limits, IP lists, allowed email domains and disposable-email blocking to osec Auth.
- AI scrapers hammering a small site? A bot gate without moving your DNS
AI crawlers now make up a large share of traffic to small sites, and many ignore robots.txt. osec Bot Gate is a two-line middleware for Node, Python or PHP: new visitors solve one invisible check, then browse for a week. Search engines pass. Nothing is proxied through us.
- We went from F to A+ on security headers with one nginx file. Grade your site
Our own site scored F: no HSTS, no Content-Security-Policy, no clickjacking protection, and a server version in every response. One shared nginx snippet took it to A+. Here's the list, and a free scanner that grades your site with copy-paste fixes.
- Certificates now expire in 200 days, soon 47. Catch it before your visitors do
Public TLS certificates dropped to a 200-day maximum in March 2026, 100 days next year and 47 days in 2029. More renewals mean more chances to break. osec Monitor watches uptime, certificate expiry and domain expiry, and emails you first.
- reCAPTCHA's free tier is now 10,000 checks a month. Here's a private, invisible swap
Google's reCAPTCHA now bills past 10,000 assessments a month. What that means for contact forms, signups and logins, and how osec Captcha replaces it with an invisible proof-of-work check: no image puzzles, no tracking, reCAPTCHA-style siteverify.
- Passwordless sign-in for any site in minutes: email codes, Google and Apple with osec.one (free)
The no-paragraph guide: what osec.one gives your site, why there's no Google or Apple OAuth setup on your side, and the exact steps from new project to working login. For existing sites, new sites, SaaS apps and larger teams. Free.
- 23andMe 2023: 14,000 reused passwords, 6.9 million people exposed
An attacker logged in to about 14,000 23andMe accounts with passwords leaked from other sites, then used a data-sharing feature to scrape profiles of 6.9 million people. How the credential stuffing campaign worked, the warning signs that were missed, and what the UK regulator said should have been in place.
- British Airways 2018: 22 lines of JavaScript and a £20 million fine
In 2018 attackers used a supplier's login to get into British Airways' network, then added 22 lines to a JavaScript library on the payment page. For two weeks card details went to a look-alike domain. A walkthrough of the Magecart skimming chain, how it was found, and the controls that would have broken it.
- MGM and Caesars 2023: when the help desk resets MFA for the attacker
In 2023 Scattered Spider skipped password cracking and phoned IT support instead, asking for passwords and MFA to be reset on privileged accounts. MGM put the cost at about $100 million. How help-desk social engineering works step by step, and the verification and identity controls that stop it.
- Uber 2022: how push-notification fatigue turned one bought password into admin access
In September 2022 an attacker with a contractor's stolen password kept sending MFA push requests until one was approved, then found admin credentials in a script on a network share. A step-by-step look at MFA fatigue, why plain push approval is weak, and the controls that break each step.
- npm 12 and the 2026 GitHub Actions hardening: what changes in your pipeline
After a run of worm-style npm compromises and mass GitHub Actions backdoors, GitHub shipped its biggest set of supply-chain defaults yet: install scripts off in npm 12, staged publishing, safer pull_request_target, read-only caches and a network firewall for runners. What each change does and what to update this week.
- Tycoon2FA: how a phishing kit walked past MFA at 500,000 organisations a month
Tycoon2FA sold adversary-in-the-middle phishing as a subscription. It relayed real logins to Microsoft and Google, let victims complete their MFA, then kept the session cookie. A breakdown of the kit, why codes and push prompts didn't help, and what does.
- Polyfill.io: when a trusted script tag turned against 380,000 sites
Hundreds of thousands of websites loaded JavaScript from cdn.polyfill.io. After the domain changed hands, it started serving code that redirected some mobile visitors to scam sites, and tried hard not to be seen. How the attack worked and how SRI, CSP and self-hosting would have contained it.
- Snowflake 2024: how years-old infostealer logs opened 165 data warehouses
The 2024 Snowflake customer breaches weren't a Snowflake vulnerability. Attackers logged in with passwords stolen by infostealer malware, some as old as 2020, and used plain SQL to stage and download whole tables. A walkthrough of the method and the three gaps it relied on.
- How a quiet password spray reached Microsoft's leadership inboxes
Midnight Blizzard didn't use an exploit to get into Microsoft's corporate email. It guessed one password on a forgotten test account, then chained OAuth apps until it could read mailboxes. Here is the chain, step by step, and the controls that break each link.