<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Brandon Pugh&#39;s Blog</title>
    <link>https://www.brandonpugh.com/tags/security/</link>
    <description>Recent content in Security on Brandon Pugh&#39;s Blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <lastBuildDate>Mon, 01 Dec 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://www.brandonpugh.com/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Anyone can be scammed</title>
      <link>https://www.brandonpugh.com/blog/anyone-can-be-scammed/</link>
      <pubDate>Tue, 25 Mar 2025 00:00:00 +0000</pubDate>
      
      <guid>https://www.brandonpugh.com/blog/anyone-can-be-scammed/</guid>
      <description>&lt;p&gt;Even Troy Hunt (a well-known security researcher and creator of &lt;a href=&#34;https://haveibeenpwned.com/&#34;&gt;Have I Been Pwned&lt;/a&gt;) fell for a phishing email.&lt;br&gt;
He wrote all about it on his blog:
&lt;a href=&#34;https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/&#34;&gt;A Sneaky Phish Just Grabbed my Mailchimp Mailing List&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I found it a valuable read, not only for the lessons learned, but it&amp;rsquo;s also a reminder that it could have happened to any of us.
The email looks fairly well crafted and I appreciated his analysis of the factors that led to him falling victim.
It&amp;rsquo;s important to remember that even the most security-minded people can make mistakes and that security is hard.&lt;/p&gt;
&lt;p&gt;Honestly the most frustrating part of the story is the fact that Mailchimp doesn&amp;rsquo;t delete unsubscribed emails and even worse they give you no way to opt out of that — so a list owner would have to regularly go in an delete them manually&amp;hellip; and why do they store your IP address?? 😡&lt;/p&gt;
&lt;p&gt;I also thought it was sneaky that they generated an api key on his account. So in addition to updating login credentials remember to check for any recently added api keys.&lt;/p&gt;
&lt;p&gt;I hadn&amp;rsquo;t thought of this vector before, but it&amp;rsquo;s now one more reason why I prefer subscribing via RSS.&lt;/p&gt;
&lt;p&gt;P.S. ButtonDown has a nice &lt;a href=&#34;https://docs.buttondown.com/subscriber-cleanup&#34;&gt;Subscriber cleanup&lt;/a&gt; feature.&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/blog/anyone-can-be-scammed/feed&quot;&gt;
      </description>
    </item>
    
  </channel>
</rss>