Report URI

@report-uri.bsky.social

We're the market leader in browser security technologies, enabling you to detect and mitigate attacks, fast.

ClickFix tricks users into compromising their own machines and hides its payload on a blockchain. But the attack still begins the same way: a website runs JavaScript it was never meant to run. That’s where we could have stopped it. blog.report-uri.com/the-clickfix...

The ClickFix Attack We Could Have Stopped

A customer forwarded us something last week that has stuck with me. It was a live attack campaign — a good one, in the professional-admiration sense — along with a detailed public write-up dissecting ...

blog.report-uri.com

Stripe just made CSP a compliance requirement. Merchants completing their annual PCI assessment are now asked to attest that they’ve deployed a Content Security Policy. That’s a major shift from “you should deploy CSP” to “confirm that you have.” Full details: blog.report-uri.com/stripe-now-a...

Stripe Now Asks You to Attest That You've Deployed a CSP

Stripe's PCI assessment now has a mandatory checkbox: confirm you've deployed a Content Security Policy. Here's what you're attesting to, and how to do it.

blog.report-uri.com

Onboarding just got a whole lot easier! 🤖 Using Claude, ChatGPT, Gemini, or another AI agent? Login, click "Copy Prompt", paste it into your AI, and it'll configure CSP reporting for you. Get up and running in minutes 😎 report-uri.com

Bild

Q2 is off to a busy start at Report URI 🚀 🔹 API/MCP endpoints GA 🔹 Audit Trail to Webhook 🔹 Custom Fingerprints for JS 🔹 Audit Archive for JS 🔹 Reporting API in @firefox.com 🔹 Deeper CSP inspection 🔹 Passkeys research + whitepaper 🔹 New Threat Intel research blog.report-uri.com/newsletter-a...

Newsletter - Apr 2026

As we continue to push into 2026, we’ve maintained our pace of improving existing features and introducing new ones. API and MCP endpoints - now Generally Available 🤖 Our API and MCP endpoints are...

blog.report-uri.com

The NCSC is right to push passkeys. They’re a huge step forward for authentication: phishing-resistant, no shared secret on the server, far better than passwords in many ways. But passkeys don’t make your application trustworthy after login!

At the scale we operate at, “one in a billion” problems can happen every single day! In our latest blog post, we share some of the challenges that come with operating Redis at scale, and what it takes to keep a high-volume telemetry pipeline fast and resilient. scotthelme.co.uk/when-one-in-...

When “One in a Billion” Happens Every Day: Scaling Redis at Report URI

Something that I've come to learn as we continue to grow Report URI is that everything is easy until scale makes it hard. We're now processing so much telemetry that a "one in a billion" problem can h...

scotthelme.co.uk

Big update from Report URI 🚀 ✅ Report Sampling in Open Beta ✅ Audit Trail in Open Beta ✅ Alert thresholds for all Watch products ✅ New Magecart case study ✅ CSP Integrity webinar recording live ✅ Find us at NDC Security Oslo 4–5 Mar, CyberUK Glasgow 21–23 Apr blog.report-uri.com/newsletter-f...

Newsletter - Feb 2026

After kicking 2026 off with a pretty big update, we've continued to push forwards with a lot of work across the board at Report URI HQ.

blog.report-uri.com

As is tradition, we've completed our annual penetration test and the results have been published publicly for all to see! Curious what was found, what we've done to resolve issues, or what a penetration test report looks like? Come and have a read! scotthelme.co.uk/report-uri-p...

Report URI Penetration Test 2025

Every year, just as we start to put up the Christmas Tree, we have another tradition at Report URI which is to conduct our annual penetration test! 🎅🎄🎁 --> 🩻🔐🥷 This will be our 6th annual penetratio...

scotthelme.co.uk