Skip to main content

Security

Showing posts tagged with "Security".

risk3sixty and Its Armada Team Achieves CREST Accreditation for Penetration Testing

We are proud to announce that risk3sixty and its elite Armada team has officially achieved CREST Accreditation for Penetration Testing, one of the mos…

Read more

Hardware Hacking: Discovering a DoS in NetGear Router

Introduction While testing internet-connected devices for vulnerabilities, our team discovered a Denial of Service (DoS) condition in a Netgear router…

Read more

Exploiting SharePoint Permissions the Co-Pilot Way

Copilot makes identifying mis-configurations in SharePoint much faster and easier to see. It honors existing permissions via Microsoft Graph: if a use…

Read more

Security Advisory - Microsoft 365 Direct Send Abuse in Active Phishing Campaigns

Security Advisory The Armada team has observed active exploitation of an ongoing security risk in M365. Due to the low effort required to exploit this…

Read more

JWT Abuse in Modern Web Apps: How a Misconfigured Token Leads to Full Access 

Introduction JSON Web Tokens (JWTs) have become a cornerstone of modern web application authentication. Their stateless nature and flexibility make th…

Read more

Inside the Black Basta Chat Leaks — and How to View Them for Yourself

Late on the evening of February 11th, 2025, a brand‑new Telegram channel named shopotbasta (“Basta Whisper” in Russian) lit up with a link to a 1 GB M…

Read more

Breaking Into GitLab: Attacking and Defending Self-Hosted CI/CD Environments

In this blog post, we will discuss attacking a self-hosted GitLab instance. GitLab is an open-core CI/CD platform that allows for the development and …

Read more

The Impact of Attack Surface Management in Mortgage Servicing

In the constantly evolving financial services landscape, where security threats are significant, and regulatory pressures are abundant, staying ahead …

Read more

Transferring Visual Studio Projects to MinGW-w64 

As penetration testers and red team operators, we often find ourselves conducting engagements from Linux-based operating systems. This preference is p…

Read more

From Reactive to Proactive: The Value of Offensive Security 

Threat actors constantly evolve and innovate, leaving organizations vulnerable to attacks from an ever-growing list of tactics and techniques. While r…

Read more

Leveraging ‘Rubeus’ for Active Directory Penetration Testing (Part One) 

The rapidly evolving, complex cybersecurity landscape places Active Directory (AD) at the forefront of many cyber threats. As a crucial component of n…

Read more

Backdoor Techniques for Remote Control on Embedded Devices

In our daily lives, we interact with a myriad of devices. Many of which may seem simple on the surface, but in fact, are powered by sophisticated tech…

Read more

Tags

See all