Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us

Lean Security

Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us
January 11, 2026
Lean Security Expert
The ToolShell Crisis: Why Your SharePoint ...

The Australian Cyber Security Centre has issued urgent warnings about actively exploited vulnerabilities in Microsoft SharePoint Server (CVE-2025-53770) that enable unauthenticated remote code execution. With Chinese state-aligned actors and ransomware groups already compromising Australian organisations, this threat represents an immediate and severe risk to business-critical data and infrastructure.

The ToolShell Crisis: Why Your SharePoint Server Is a Ticking Time Bomb
December 27, 2025
Lean Security Expert
Why Long-Lived Cloud Credentials Are Your ...

Across AWS, Google Cloud, and Microsoft Azure environments in Australia and globally, 59% of IAM users maintain access keys that have never expired—credentials that have been active for more than one year. These long-lived credentials represent a silent but catastrophic vulnerability in your cloud infrastructure. This blog explores why long-lived credentials have become the primary attack vector for identity-based breaches, how red teams exploit them during penetration tests, and what you must do today to eliminate this ticking time bomb.

Why Long-Lived Cloud Credentials Are Your Biggest Identity Risk in 2025
December 21, 2025
Lean Security Expert
Fortinet "Ghost Logins": How Authentication ...

Critical authentication bypass vulnerabilities in Fortinet FortiGate and related products (CVE-2025-59718 and CVE-2025-59719) are now under active attack, allowing "ghost" SSO logins that completely sidestep normal controls and logs. For Australian organisations, this is more than a VPN or firewall problem – it is a board-level exposure that directly tests whether your external penetration testing, internal penetration testing, and red team assessment services are capable of simulating SSO abuse, identity takeovers, and lateral movement across hybrid networks.

Fortinet "Ghost Logins": How Authentication Bypass Attacks Expose Gaps in Your Penetration Testing Strategy
December 6, 2025
Lean Security Expert
React2Shell: A CISO’s Guide to CVE-2025-55182

A new security flaw called React2Shell (CVE-2025-55182) puts Australian businesses at extreme risk. It has a severity score of CVSS 10.0, which is the highest possible rating. This flaw lets hackers take full control of your servers without needing a password. It affects the popular tools React and Next.js.

React2Shell: A CISO’s Guide to CVE-2025-55182
November 26, 2025
Lean Security Expert
SessionReaper & BFCM: Why Penetration ...

A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)
Lean Security Expert
August 22, 2017

Web Security Issues You’re Not Addressing

Lean Security Expert
August 22, 2017
Web Security Issues You’re Not Addressing

Back in 2013, a popular research study by the National Institute of Standards and Technology concluded that inadequate web security and tools cost the economy as much as $22.2 billion annually

Comment
Lean Security Expert
August 18, 2017

Conducting Web Application Testing On Your Own? This Checklist Will Help

Lean Security Expert
August 18, 2017

All business owners want their websites to work smoothly and leave the right impression on their customers. Apart from the web design and how web applications seem on the surface, there’s a lot that can be done to prevent unpleasant surprises.

Comment
Lean Security Expert
August 14, 2017

Application Security Is Fraught With Mystery – 3 Myths Busted

Lean Security Expert
August 14, 2017
Application Security Is Fraught With Mystery – 3 Myths Busted

It is not surprising to see that many companies continue to grapple with application security.

Comment
Lean Security Expert
August 10, 2017

3 PCI Compliance Mistakes You Need to Stop Making Today!

Lean Security Expert
August 10, 2017
3 PCI Compliance Mistakes You Need to Stop Making Today!

With the digital business environment falling victim to breaches and hacks every day, it is now more important than ever to protect your business operations by ensuring safety for customer data.

Comment
Lean Security Expert
July 24, 2017

Web Application Mistakes That Lead To Security Risks

Lean Security Expert
July 24, 2017
Web Application Mistakes That Lead To Security Risks

According to a research study conducted by WhiteHat:

· 8 out of 10 web sites have serious flaws

· 71% of Web sites are vulnerable to cross-site scripting (XSS) ...

Comment
Lean Security Expert
July 21, 2017

Testing For Application Security—Can You Skip It?

Lean Security Expert
July 21, 2017
Testing For Application Security—Can You Skip It?

As technology continues to imbed itself in practically all aspects of our daily lives, the risk of crucial information—business and personal—being leaked becomes more real.

Many major companies like Google now offer massive cash rewards to hackers who can expose vulnerabilities in web applications and websites.

Comment
Lean Security Expert
July 18, 2017

Major Challenges That Hamper Penetration Testing

Lean Security Expert
July 18, 2017

Penetration testing is a part of the software testing process that helps identify how the application responds to various breaches and attacks. However, with technologies advancing rapidly, the threats are becoming more complex and even harder to avert.

Comment
Lean Security Expert
July 15, 2017

Boost Customer Satisfaction By Maintaining Web Security

Lean Security Expert
July 15, 2017
Boost Customer Satisfaction By Maintaining Web Security

There are many elements on the internet, who would like nothing more than to deface your website and place inappropriate content on it.

Comment
Lean Security Expert
July 12, 2017

Why Choose Lean Security For Your Web Security Testing Needs?

Lean Security Expert
July 12, 2017
Why Choose Lean Security For Your Web Security Testing Needs?

At Lean Security, we are dedicated to protecting you, your business and your clients from hacks and data breaches. We provide proactive managed IT security solutions that are reliable, effective and hands down the best in the market.

Comment
Lean Security Expert
July 8, 2017

Simple Tips For Security Testing Web Applications

Lean Security Expert
July 8, 2017
Simple Tips For Security Testing Web Applications

Web applications offer a wide range of benefits for developers. One of the best parts about web applications is that they don’t need to be installed, therefore, there is no burden regarding patches or updates on users.

Comment
Newer Posts
Older Posts
Contact us for a quote
Back to Top
Lean Security, 81-83 Campbell Street, Surry Hills, NSW, 2010, Australia+61 (2) 8078 6952info@leansecurity.com.au

About Lean Security

We are a specialist cybersecurity firm based in Sydney, focusing on penetration testing. We partner with organisations across Australia, providing expert-led testing and clear, actionable reports. Our goal is to give you the clarity and confidence needed to secure your digital assets.

     
Useful Links
Home
Application penetration testing
Security source code assessment
Mobile application penetration testing
Infrastructure penetration testing
API web services penetration testing
Threat Modelling Service

Newsletter

We respect your privacy.

Thank you!

Contact Us

Phone: +61 (2) 8078 6952
Email: info@leansecurity.com.au

Monday - Friday from 9.00 am to 8.00 pm
Saturday from 10.00 am to 6.00 pm