Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us

Lean Security

Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us
January 11, 2026
Lean Security Expert
The ToolShell Crisis: Why Your SharePoint ...

The Australian Cyber Security Centre has issued urgent warnings about actively exploited vulnerabilities in Microsoft SharePoint Server (CVE-2025-53770) that enable unauthenticated remote code execution. With Chinese state-aligned actors and ransomware groups already compromising Australian organisations, this threat represents an immediate and severe risk to business-critical data and infrastructure.

The ToolShell Crisis: Why Your SharePoint Server Is a Ticking Time Bomb
December 27, 2025
Lean Security Expert
Why Long-Lived Cloud Credentials Are Your ...

Across AWS, Google Cloud, and Microsoft Azure environments in Australia and globally, 59% of IAM users maintain access keys that have never expired—credentials that have been active for more than one year. These long-lived credentials represent a silent but catastrophic vulnerability in your cloud infrastructure. This blog explores why long-lived credentials have become the primary attack vector for identity-based breaches, how red teams exploit them during penetration tests, and what you must do today to eliminate this ticking time bomb.

Why Long-Lived Cloud Credentials Are Your Biggest Identity Risk in 2025
December 21, 2025
Lean Security Expert
Fortinet "Ghost Logins": How Authentication ...

Critical authentication bypass vulnerabilities in Fortinet FortiGate and related products (CVE-2025-59718 and CVE-2025-59719) are now under active attack, allowing "ghost" SSO logins that completely sidestep normal controls and logs. For Australian organisations, this is more than a VPN or firewall problem – it is a board-level exposure that directly tests whether your external penetration testing, internal penetration testing, and red team assessment services are capable of simulating SSO abuse, identity takeovers, and lateral movement across hybrid networks.

Fortinet "Ghost Logins": How Authentication Bypass Attacks Expose Gaps in Your Penetration Testing Strategy
December 6, 2025
Lean Security Expert
React2Shell: A CISO’s Guide to CVE-2025-55182

A new security flaw called React2Shell (CVE-2025-55182) puts Australian businesses at extreme risk. It has a severity score of CVSS 10.0, which is the highest possible rating. This flaw lets hackers take full control of your servers without needing a password. It affects the popular tools React and Next.js.

React2Shell: A CISO’s Guide to CVE-2025-55182
November 26, 2025
Lean Security Expert
SessionReaper & BFCM: Why Penetration ...

A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)
Lean Security Expert
February 15, 2018

Reasons Why Mobile App Security Testing is Vital -Infographic

Lean Security Expert
February 15, 2018
Reasons Why Mobile App Security Testing is Vital -Infographic

n today's era, security has become the necessity. Online security for online assets is mandatory to secure online data and assets. Mobile application security is need and vital as well. Mobile app security prevent attack and the steps involved

Comment
Lean Security Expert
February 1, 2018

Is Cloud Hosting Secure?

Lean Security Expert
February 1, 2018
Is Cloud Hosting Secure?

Cloud hosting or cloud computing is a great way to reduce costs and improve the overall efficiency of the IT function for businesses.

Comment
Lean Security Expert
January 29, 2018

Protect Your Site from Vulnerabilities – Why You Should Have a Scan

Lean Security Expert
January 29, 2018

Having a professional looking business website, the right SEO procedures and an effective marketing strategy is only half the battle for any online business.

Comment
Lean Security Expert
January 24, 2018

Predicting 2018 Cyber Security Solutions

Lean Security Expert
January 24, 2018
Predicting 2018 Cyber Security Solutions

2017 was pretty rough when it comes to cybercrimes. Experts predict that 2018 may be even worse. Cyber-attacks are becoming more advanced and sophisticated as the years go by, and prove to be devastating for some businesses

Comment
Lean Security Expert
January 18, 2018

Organising a Risk-Based Security Strategy for Your Online Business

Lean Security Expert
January 18, 2018

Cyber-attacks are not only increasing in number, but also in sophistication. This is why businesses need to switch from response-based approach to cyber-attacks, to identifying and preventing them before they occur

Comment
Lean Security Expert
January 15, 2018

Why PCI DSS Compliance Matters to Your Business

Lean Security Expert
January 15, 2018

While most companies are blissfully unaware of PCI DSS compliance, it matters more to their business than they give it credit for!

Comment
Lean Security Expert
January 13, 2018

The Many Benefits of Network Vulnerability Assessment

Lean Security Expert
January 13, 2018
The Many Benefits of Network Vulnerability Assessment

In today’s digital age, cyber-attacks are inevitable. Recent numbers posted by Barkly paint a grim picture. 56% of the organisations surveyed were victims of cyber-attacks in 2016 alone.

Comment
Lean Security Expert
January 10, 2018

How to Guarantee Mobile Application Security

Lean Security Expert
January 10, 2018
How to Guarantee Mobile Application Security

One of the biggest industries of our time is the mobile app ecosystem. Recent research studies show that there are more than 2.32 billion smart phone users in the world and that these apps are part of a trillion dollar industry!

Comment
Lean Security Expert
January 8, 2018

Bulk Up On Web Application Security by Following These 3 Tips

Lean Security Expert
January 8, 2018
Bulk Up On Web Application Security by Following These 3 Tips

Fortifying a website or online business module against cyber-attacks is easier said than done. While you might think that your business has nothing to offer hackers so it’s pretty safe as is, but that simple isn’t the case!

Comment
Lean Security Expert
November 16, 2017

Five Security Tips For Your E-Commerce Website - Infographic

Lean Security Expert
November 16, 2017

Read the useful security tips for your E-commerce website.

Comment
Newer Posts
Older Posts
Contact us for a quote
Back to Top
Lean Security, 81-83 Campbell Street, Surry Hills, NSW, 2010, Australia+61 (2) 8078 6952info@leansecurity.com.au

About Lean Security

We are a specialist cybersecurity firm based in Sydney, focusing on penetration testing. We partner with organisations across Australia, providing expert-led testing and clear, actionable reports. Our goal is to give you the clarity and confidence needed to secure your digital assets.

     
Useful Links
Home
Application penetration testing
Security source code assessment
Mobile application penetration testing
Infrastructure penetration testing
API web services penetration testing
Threat Modelling Service

Newsletter

We respect your privacy.

Thank you!

Contact Us

Phone: +61 (2) 8078 6952
Email: info@leansecurity.com.au

Monday - Friday from 9.00 am to 8.00 pm
Saturday from 10.00 am to 6.00 pm