logo

Pen Test Partners Blog

ID: a85b6f9a-c3e6-5257-86f2-f6aaaee2afb6

STIX ID: identity--a85b6f9a-c3e6-5257-86f2-f6aaaee2afb6

Feed Type: rss

Earliest post: 2023-11-23

Latest post: 2026-06-12

Practical penetration-testing insights, deep technical analyses, attack techniques, and defence strategies from experienced security consultants.

01/01/2020
06/13/2026
Title Date Published Describes IncidentAuthorVisible
ClickFix, CrashFix and the growing family of copy and paste attacks 2026-06-10TrueAlex WallaceTrue
Shelly Wall Display exposed RPC over Bluetooth 2026-05-26TrueAlex WallaceTrue
Insecure IAM is the root of many cloud security failures2026-03-24TrueAlex WallaceTrue
EV batteries as grid infrastructure and the security risk that follows 2026-02-24TrueAlex WallaceTrue
Shelly IoT door controller config fail: leaving your garage, home and security exposed2026-02-11TrueAlex WallaceTrue
Carlsberg… probably not the best cybersecurity in the world2026-01-16TrueAlex WallaceTrue
Compromising a multi-cloud environment from a single exposed secret 2026-01-13TrueAlex WallaceTrue
2025, the year of the Infostealer 2026-01-06TrueAlex WallaceTrue
Eurostar AI vulnerability: when a chatbot goes off the rails2025-12-22TrueAlex WallaceTrue
Discord as a C2 and the cached evidence left behind2025-09-16TrueAlex WallaceTrue
Terraform Cloud token abuse turns speculative plan into remote code execution2025-08-15TrueAlex WallaceTrue
Our capabilities. A story about what we can achieve2025-07-28TrueJoe BursellTrue
Leaked data. Continuous glucose monitoring2025-07-22TrueJoe BursellTrue
Framework 13. Press here to pwn 2025-07-16TrueAlex WallaceTrue
Sil3ncer Deployed – RCE, Porn Diversion, and Ransomware on an SFTP-only Server2025-07-11TrueJoe BursellTrue
Pet microchip scams and data leaks in the UK2025-07-04TrueJoe BursellTrue
CSP directives. Base-ic misconfigurations with big consequences2025-06-23TrueJoe BursellTrue
Android AI UX is great until it leaks your data2025-06-17TrueJoe BursellTrue
Fire detection system been pwned? You’re not going to sea2025-05-30TrueJoe BursellTrue
The remote desktop puzzle. DFIR techniques for dealing with RDP Bitmap Cache2025-05-01TrueJoseph WilliamsTrue
Backdoor in the Backplane. Doing IPMI security better2025-03-31TrueKieran LarkingTrue
DNSSEC NSEC. The accidental treasure map to your subdomains2025-03-04TrueDarrell HallTrue
Watch where you point that cred! Part 12025-02-18TrueTom Thomas-LitmanTrue
ICS testing best results. Hint: Blend your approach2025-02-07TrueAndrew TierneyTrue
A tale of enumeration, and why pen testing can’t be automated2025-02-05TrueMorgan DaviesTrue
Security flaws found in tiny phones promoted to children2025-01-15TrueJoe LovettTrue
The unexpected effects of GPS spoofing on aviation safety2025-01-09TruePTP Aviation TeamTrue
Heels on fire. Hacking smart ski socks2024-12-23TrueKen MunroTrue
How easily access cards can be cloned and why your PACS might be vulnerable2024-12-11TrueWarren HoughtonTrue
Did security gaps at Antwerp port enable drug smuggling operations?2024-11-12TrueKen MunroTrue
You lost your iPhone, but it’s locked. That’s fine, right?2024-11-06TrueNicole MoineTrue
Mounting memory with MemProcFS for advanced memory forensics2024-10-31TrueLuke DavisTrue
Airbus Navblue Flysmart LPC-NG issues2024-10-01TruePTP Aviation TeamTrue
Direct Memory Access (DMA) attacks. Risks, techniques, and mitigations in hardware hacking2024-09-26TrueRachel RabinTrue
Proroute H685 4G router vulnerabilities2024-09-19TrueJoe LovettTrue
Smart home security advice. Ring, SimpliSafe, Swann, and Yale2024-09-10TrueAdam BromileyTrue
RCE vulnerability in OpenSSH – RegreSSHion (CVE-2024-6387)2024-07-02TrueEime AdomaviciuteTrue
Glastonbury ticket hijack vulnerability fixed2024-06-28TrueLewis KTrue
Pipedream ICS malware toolkit is a nightmare2024-05-09TrueLuke DavisTrue
Vulnerabilities that (mostly) aren’t: LUCKY132024-05-03TrueDavid LodgeTrue
Bypassing MFA on Microsoft Azure Entra ID2024-05-01TrueJack Barradell-JohnsTrue
Living off the land with native SSH and split tunnelling2024-03-06TrueJoe BlogsTrue
No fix KrbRelay VMware style2024-02-21TrueCeri CoburnTrue
Ski & bike helmets protect your head, not location or voice2024-02-07TrueCeri Coburn and Joe BlogsTrue
Hacking Electronic Flight Bags. Airbus NAVBLUE Flysmart+ Manager2024-02-01TrueAntonio CassidyTrue
RAID Technology and the importance of disk encryption in data security2024-01-04TrueVladimir Panek-NobleTrue
Mobile malware analysis for the BBC2024-01-02TrueDaniel GildersleeveTrue
Helping a banking fraud victim2024-01-02TrueKen MunroTrue
Helping a mobile malware fraud victim2024-01-02TrueKen MunroTrue
Intercepting MFA. Phishing and Adversary in The Middle attacks2023-12-12TrueAdam HarwoodTrue

1–50 of 51