Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us

Lean Security

Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us
December 27, 2025
Lean Security Expert
THE CREDENTIAL TIME BOMB: Why Long-Lived Cloud ...

Across AWS, Google Cloud, and Microsoft Azure environments in Australia and globally, 59% of IAM users maintain access keys that have never expired—credentials that have been active for more than one year. These long-lived credentials represent a silent but catastrophic vulnerability in your cloud infrastructure. This blog explores why long-lived credentials have become the primary attack vector for identity-based breaches, how red teams exploit them during penetration tests, and what you must do today to eliminate this ticking time bomb.

THE CREDENTIAL TIME BOMB: Why Long-Lived Cloud Credentials Are Your Biggest Identity Risk in 2025
December 21, 2025
Lean Security Expert
Fortinet "Ghost Logins": How Authentication ...

Critical authentication bypass vulnerabilities in Fortinet FortiGate and related products (CVE-2025-59718 and CVE-2025-59719) are now under active attack, allowing "ghost" SSO logins that completely sidestep normal controls and logs. For Australian organisations, this is more than a VPN or firewall problem – it is a board-level exposure that directly tests whether your external penetration testing, internal penetration testing, and red team assessment services are capable of simulating SSO abuse, identity takeovers, and lateral movement across hybrid networks.

Fortinet "Ghost Logins": How Authentication Bypass Attacks Expose Gaps in Your Penetration Testing Strategy
December 6, 2025
Lean Security Expert
React2Shell: A CISO’s Guide to CVE-2025-55182

A new security flaw called React2Shell (CVE-2025-55182) puts Australian businesses at extreme risk. It has a severity score of CVSS 10.0, which is the highest possible rating. This flaw lets hackers take full control of your servers without needing a password. It affects the popular tools React and Next.js.

React2Shell: A CISO’s Guide to CVE-2025-55182
November 26, 2025
Lean Security Expert
SessionReaper & BFCM: Why Penetration ...

A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)
November 12, 2025
Lean Security Expert
CISA Alert: LANDFALL Spyware Hits Australian ...

A zero-click vulnerability, CVE-2025-21042, in millions of Samsung devices is being actively exploited to install "LANDFALL," a commercial-grade spyware. This threat, now on CISA's KEV catalog , transforms an executive's personal device into a silent corporate surveillance tool, completely bypassing your MDM and EDR. For Australian organisations with BYOD policies, this is a critical, reportable data breach scenario under the NDB scheme.

CISA Alert: LANDFALL Spyware Hits Australian BYOD Devices
Lean Security Expert
May 30, 2018

The General Data Protection Regulation Guidelines For Businesses In Australia

Lean Security Expert
May 30, 2018

The General Data Protection Regulation contains details regarding the protection of data within a region. The act will replace the national data protection laws within the region

Comment
Lean Security Expert
May 29, 2018

Network Vulnerability Assessment And Their Benefits For Businesses

Lean Security Expert
May 29, 2018

Cyber security threats are a major issue that can have a significant impact on Australia’s economy and prosperity. Some of the examples of cyber threats include:

Comment
Lean Security Expert
May 28, 2018

Ensure That Your Cloud Systems Stay Safe and Secure Through Automation

Lean Security Expert
May 28, 2018

When it comes to cloud based systems, the words ‘automation’ and ‘orchestration’ are synonymous.

Comment
Lean Security Expert
April 23, 2018

Streamlining Your Netwrok Security - The Need For Regular Vulnerability Assessment- Infographic

Lean Security Expert
April 23, 2018
Streamlining Your Netwrok Security - The Need For Regular Vulnerability Assessment- Infographic

The need for regular vulnerability assessment is need for ever business online to provide network security against threats.

Comment
Lean Security Expert
April 20, 2018

Cryptocurrency Mining Malware – 2018’s New Menace!

Lean Security Expert
April 20, 2018
Cryptocurrency Mining Malware – 2018’s New Menace!

With digital currency slowly gaining popularity over the past 8 years, the biggest question that arises is, is it a safe investment to make? Cryptocurrency depends on cryptography for distribution and transferring.

Comment
Lean Security Expert
April 16, 2018

Secure Code Review – The Best Practices

Lean Security Expert
April 16, 2018
Secure Code Review – The Best Practices

Nearly two years ago, a hosting provider deleted his entire company because of a small mistake. The mistake, you ask? A single destructive line of code

Comment
Lean Security Expert
April 12, 2018

Common and Deadly Security Mistakes Coders Make

Lean Security Expert
April 12, 2018
Common and Deadly Security Mistakes Coders Make

The truth is, most businesses don’t think twice about application vulnerability, which is the real culprit that allows “hacktivists” to penetrate through security systems

Comment
Lean Security Expert
April 9, 2018

A Beginner’s Guide to DDoS Attack and Protection

Lean Security Expert
April 9, 2018
A Beginner’s Guide to DDoS Attack and Protection

Wondering how do you DDoS proof a network? We explain the mechanics of Distributed Denial of Service (DoS) attacks, botnets, and how to implement effective protection.

Tagged: Web Application Security

Comment
Lean Security Expert
March 7, 2018

Why a Network Vulnerability Assessment is good for Business

Lean Security Expert
March 7, 2018
Why a Network Vulnerability Assessment is good for Business

Cyber attacks have cost companies and businesses a fair bit, both in terms of money and in terms of information/intellectual property according to international statistics.

Comment
Lean Security Expert
March 3, 2018

Things to Look Out for When Hiring a Managed Network Security Service

Lean Security Expert
March 3, 2018
Things to Look Out for When Hiring a Managed Network Security Service

Given that cybercrime, network security breaches and organizational data penetration and theft can cost a pretty penny statistically speaking, it makes sense to stay protected.

Comment
Newer Posts
Older Posts
Contact us for a quote
Back to Top
Lean Security, 81-83 Campbell Street, Surry Hills, NSW, 2010, Australia+61 (2) 8078 6952info@leansecurity.com.au

About Lean Security

We are a specialist cybersecurity firm based in Sydney, focusing on penetration testing. We partner with organisations across Australia, providing expert-led testing and clear, actionable reports. Our goal is to give you the clarity and confidence needed to secure your digital assets.

     
Useful Links
Home
Application penetration testing
Security source code assessment
Mobile application penetration testing
Infrastructure penetration testing
API web services penetration testing
Threat Modelling Service

Newsletter

We respect your privacy.

Thank you!

Contact Us

Phone: +61 (2) 8078 6952
Email: info@leansecurity.com.au

Monday - Friday from 9.00 am to 8.00 pm
Saturday from 10.00 am to 6.00 pm