Full access to production via unauthenticated internal API
Admin endpoint exposed by API gateway misconfig. Combined with IDOR in transfer routes, allowed pivot to any account. Identified on day 2 of the engagement.
All cases below were anonymized under NDA. Numbers, sector and vector are real — client name is not.
Admin endpoint exposed by API gateway misconfig. Combined with IDOR in transfer routes, allowed pivot to any account. Identified on day 2 of the engagement.
Staging bucket replicated production data without encryption or access control. Fixed before external ISO audit.
Red Team engagement starting from phishing. Pivot from engineering station to OT network via VPN with default credentials. Fixed with segmentation + jump host + MFA.
Reflected XSS on search page combined with permissive cookie policy allowed admin session theft. Identified in standard pentest.
Publishing a customer's name alongside the flaw they had exposes them twice: once during the incident and once permanently. Describing the vector and the impact teaches something; identifying the victim is just a shop window — and it skews the incentive, because the company willing to authorise disclosure becomes the one with least to lose.
Different sectors, different architectures — and still the routes that work look alike. These are the ones that come up most often, and they are worth looking at before commissioning any test.
Staging with a copy of production, an old admin panel, a service spun up for a demo and never switched off. It is usually missing from the inventory and therefore outside every protection applied to everything else.
The system checks that you are authenticated but not that the record is yours. It is the flaw automated tooling misses most often, because the request looks perfectly legitimate.
Broad access granted to unblock a delivery, with a promise to tighten it later. Months on it is still there, now inherited by people who never knew they had it.
A key in an exposed environment variable, a credential in repository history, a token in a versioned config file. It is the shortest path in and the easiest to close.
Two applications that authenticate to each other by network position or a shared secret. Compromising the less protected one delivers the better protected one, and the segmentation meant to contain that has rarely been tested.
The event was logged, the alert fired — and landed in a queue nobody reads. Technically detected, practically invisible: the difference only shows up in an unannounced exercise.
Because authorisation to publish would come from whoever has least to lose, not from whoever had the most instructive case. All material is anonymised under a confidentiality agreement, and the technical vector — the useful part — is preserved.
Yes, subject to authorisation from the parties involved. For most processes, though, what settles it is the closing letter from your own engagement, issued after retest: that is direct evidence, rather than a third party's opinion about someone else's work.
No. The route depends on architecture, integrations and decisions that only surface in your environment. The cases show the kind of thing that tends to be found, not a script that repeats.
Never. Nothing becomes public text before remediation is complete and confirmed by retest, and even then only with authorisation. The same criterion governs our own research, set out in the responsible disclosure policy.
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.