logo

Hackers exploit security testing apps to breach Fortune 500 firms

ID: 121ac300-1ee7-5159-951e-16e536700796

STIX ID: report--121ac300-1ee7-5159-951e-16e536700796

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-01-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Pentera found nearly 2,000 intentionally vulnerable security-testing web applications exposed on public cloud accounts (AWS, GCP, Azure), with evidence that attackers have actively exploited these instances to steal credentials, deploy XMRig crypto-miners, install webshells, and establish persistence — exposures that can lead to access to S3/GCS/Azure Blob, Secrets Manager, container registries, and admin cloud functions.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.