Hack of the Month

Bypassing Threatlocker With Powershell

June 2023 – We discuss and highlight how we bypassed one of the most heavily used ‘zero trust’ application whitelisting platforms. Their homepage ironically states that they block execution of

Read More »
Hack of the Month

Hidden in Plain Sight

May 2023 – In this edition, we highlight how a decommissioned application was not fully removed as expected, allowing us to abuse legacy functionality to compromise an enormous amount of

Read More »
Single Sign On Security
Hack of the Month

SAML Shenanigans

March 2023 – With single sign-on becoming more common during our assessments, we cover one of the vulnerabilities we discovered during an engagement that let us forge SAML responses to

Read More »
Hack of the Month

You Are The Weakest Link, GoodLFI

In February 2023, we completed a web application security assessment for a new client within the legal field. What followed was a series of hurdles, followed by jumps and yet

Read More »
Hack of the Month

RCE – Really Crap Encryption

In December 2022, we completed a web application security assessment for a client who wanted assurance that their newly developed application was ready for production. The application allowed users to

Read More »
Hack of the Month

NoSQL? No Problem.

In November 2022, we completed a web application security assessment for a new client within the health / wellbeing sector. We were told through previous discussions, that the web application

Read More »
Hack of the Month

Accessing the Keys to The Kingdom

In October 2022, we completed an internal security assessment for a large tech organisation with clients in the legal industry, focused around the handling of sensitive documents for other companies.

Read More »
Hack of the Month

Compromising 5,000 Servers CTF-Style

In September 2022, we completed an internal security assessment for a large client in the tech industry. The scope was enormous – about 20,000 hosts in scope split over eight

Read More »