Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us

Lean Security

Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us
January 11, 2026
Lean Security Expert
The ToolShell Crisis: Why Your SharePoint ...

The Australian Cyber Security Centre has issued urgent warnings about actively exploited vulnerabilities in Microsoft SharePoint Server (CVE-2025-53770) that enable unauthenticated remote code execution. With Chinese state-aligned actors and ransomware groups already compromising Australian organisations, this threat represents an immediate and severe risk to business-critical data and infrastructure.

The ToolShell Crisis: Why Your SharePoint Server Is a Ticking Time Bomb
December 27, 2025
Lean Security Expert
Why Long-Lived Cloud Credentials Are Your ...

Across AWS, Google Cloud, and Microsoft Azure environments in Australia and globally, 59% of IAM users maintain access keys that have never expired—credentials that have been active for more than one year. These long-lived credentials represent a silent but catastrophic vulnerability in your cloud infrastructure. This blog explores why long-lived credentials have become the primary attack vector for identity-based breaches, how red teams exploit them during penetration tests, and what you must do today to eliminate this ticking time bomb.

Why Long-Lived Cloud Credentials Are Your Biggest Identity Risk in 2025
December 21, 2025
Lean Security Expert
Fortinet "Ghost Logins": How Authentication ...

Critical authentication bypass vulnerabilities in Fortinet FortiGate and related products (CVE-2025-59718 and CVE-2025-59719) are now under active attack, allowing "ghost" SSO logins that completely sidestep normal controls and logs. For Australian organisations, this is more than a VPN or firewall problem – it is a board-level exposure that directly tests whether your external penetration testing, internal penetration testing, and red team assessment services are capable of simulating SSO abuse, identity takeovers, and lateral movement across hybrid networks.

Fortinet "Ghost Logins": How Authentication Bypass Attacks Expose Gaps in Your Penetration Testing Strategy
December 6, 2025
Lean Security Expert
React2Shell: A CISO’s Guide to CVE-2025-55182

A new security flaw called React2Shell (CVE-2025-55182) puts Australian businesses at extreme risk. It has a severity score of CVSS 10.0, which is the highest possible rating. This flaw lets hackers take full control of your servers without needing a password. It affects the popular tools React and Next.js.

React2Shell: A CISO’s Guide to CVE-2025-55182
November 26, 2025
Lean Security Expert
SessionReaper & BFCM: Why Penetration ...

A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)
Lean Security Expert
October 31, 2018

Here's How to Stop Your Network From Being Hacked

Lean Security Expert
October 31, 2018
Here's How to Stop Your Network From Being Hacked
Don’t want you network to be hacked? Here’s how to stop your network from being hacked

Comment
Lean Security Expert
October 29, 2018

Penetration Testing Trends You Need To Get Behind

Lean Security Expert
October 29, 2018
Penetration Testing Trends You Need To Get Behind

While there may be many upsides of technology, a prominent downside is the risk of cybercrimes. Cybercrimes are a major concern for businesses that operate online. Read which penetration testing trends you need to get behind.

Comment
Lean Security Expert
October 25, 2018

5 Ways Penetration Testing Can Help Your Business

Lean Security Expert
October 25, 2018
5 Ways Penetration Testing Can Help Your Business

The era of technology has contributed in expanding the business via web and mobile applications. Read what are the 5 ways penetration testing can help your business.

Comment
Lean Security Expert
October 9, 2018

Why Timely Data Breach Detection Is Key

Lean Security Expert
October 9, 2018
Why Timely Data Breach Detection Is Key

The process of data breach detection involves collecting, analysing and interpreting incoming web traffic to spot potential network threats to confidential company and client data

Comment
Lean Security Expert
October 5, 2018

Attention App Developers: Protect Your Source Code!

Lean Security Expert
October 5, 2018
Attention App Developers: Protect Your Source Code!

Software developers are faced with growing security concerns when it comes to the source codes powering their applications for users around the globe.

Comment
Lean Security Expert
October 1, 2018

Top Security Issues App Developers Should Know About

Lean Security Expert
October 1, 2018
Top Security Issues App Developers Should Know About

Mobile application development is experiencing exponential growth in the present market. This makes it necessary for mobile app developers to not only provide new features to users but to also ensure that security protocols are constantly updated.

Comment
Lean Security Expert
September 28, 2018

Benefits of Cloud-Based Testing for Mobile Applications

Lean Security Expert
September 28, 2018
Benefits of Cloud-Based Testing for Mobile Applications

Cloud-based mobile application testing uses cloud technology to enable developer access to a range of mobile devices. These devices may use different Operating System (OS) platforms and network carriers.

Comment
Lean Security Expert
September 19, 2018

Mobile Application Vulnerabilities - Infographic

Lean Security Expert
September 19, 2018

With advantages of mobile phone comes loads of hurdles and threats like cyber crime and mobile hack. All these unwanted threats lead to data loss and date security breach.

Here’s why you should be aware of the mobile application vulnuerabilities.

Comment
Lean Security Expert
September 6, 2018

How to Keep Your Data Secure On Cloud

Lean Security Expert
September 6, 2018
How to Keep Your Data Secure On Cloud

The number of people who use Cloud technology is rapidly increasing and it is expected that by the end of 2018, 3.6 billion people will be using this service. Here is how to keep your data secure on cloud,

Comment
Lean Security Expert
September 3, 2018

Signs Your Network Security Has Been Compromised

Lean Security Expert
September 3, 2018
Signs Your Network Security Has Been Compromised

Do you get random messages every time you turn on your web browser? Maybe you have an unwanted toolbar on your browser. These are just some signs that your network’s security has been compromised.

Comment
Newer Posts
Older Posts
Contact us for a quote
Back to Top
Lean Security, 81-83 Campbell Street, Surry Hills, NSW, 2010, Australia+61 (2) 8078 6952info@leansecurity.com.au

About Lean Security

We are a specialist cybersecurity firm based in Sydney, focusing on penetration testing. We partner with organisations across Australia, providing expert-led testing and clear, actionable reports. Our goal is to give you the clarity and confidence needed to secure your digital assets.

     
Useful Links
Home
Application penetration testing
Security source code assessment
Mobile application penetration testing
Infrastructure penetration testing
API web services penetration testing
Threat Modelling Service

Newsletter

We respect your privacy.

Thank you!

Contact Us

Phone: +61 (2) 8078 6952
Email: info@leansecurity.com.au

Monday - Friday from 9.00 am to 8.00 pm
Saturday from 10.00 am to 6.00 pm