logo

Bridging the Gap: Elevating Red Team Assessments with Application Security Testing

ID: f3fd0d41-34cb-54fe-b312-08755e37436b

STIX ID: report--f3fd0d41-34cb-54fe-b312-08755e37436b

Feed Name: Google Cloud Threat Intelligence

Threat Score
70/100

Date Published: 2024-12-05

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant describes integrating AppSec specialists into Red Team engagements to improve external perimeter coverage, with a case study where a decompiled mobile app revealed a hardcoded API key. Using that key, the team exploited a server-side request forgery (SSRF) and chained it to a ViewState deserialization vulnerability in an internal document management application—obtaining a reliable foothold in the target's internal network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.