Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Penetration Testing as a Service (PTaaS)
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Executive Cyber Warfare Simulation & Incident Response Testing
Virtual CISO (vCISO) Services
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us

Lean Security

Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Penetration Testing as a Service (PTaaS)
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Executive Cyber Warfare Simulation & Incident Response Testing
Virtual CISO (vCISO) Services
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us
April 3, 2026
Pen Testing
Lean Security Expert
The 2026 Shift from Annual Compliance to ...

Upgrade from annual pen tests to continuous penetration testing services in Australia. Discover 2026 red teaming trends, PTaaS, and expert security assessments.

The 2026 Shift from Annual Compliance to Continuous Penetration Testing and Red Teaming in Australia
March 1, 2026
Lean Security Expert
Cisco SD-WAN Zero-Day (CVE-2026-20127): Deep ...

Discover how threat actors exploit the critical CVE-2026-20127 Cisco SD-WAN vulnerability. Learn IoCs, remediation steps, and how penetration testing secures your network.

Cisco SD-WAN Zero-Day (CVE-2026-20127): Deep Dive & Fix
January 11, 2026
Lean Security Expert
The ToolShell Crisis: Why Your SharePoint ...

The Australian Cyber Security Centre has issued urgent warnings about actively exploited vulnerabilities in Microsoft SharePoint Server (CVE-2025-53770) that enable unauthenticated remote code execution. With Chinese state-aligned actors and ransomware groups already compromising Australian organisations, this threat represents an immediate and severe risk to business-critical data and infrastructure.

The ToolShell Crisis: Why Your SharePoint Server Is a Ticking Time Bomb
December 27, 2025
Lean Security Expert
Why Long-Lived Cloud Credentials Are Your ...

Across AWS, Google Cloud, and Microsoft Azure environments in Australia and globally, 59% of IAM users maintain access keys that have never expired—credentials that have been active for more than one year. These long-lived credentials represent a silent but catastrophic vulnerability in your cloud infrastructure. This blog explores why long-lived credentials have become the primary attack vector for identity-based breaches, how red teams exploit them during penetration tests, and what you must do today to eliminate this ticking time bomb.

Why Long-Lived Cloud Credentials Are Your Biggest Identity Risk in 2025
December 21, 2025
Lean Security Expert
Fortinet "Ghost Logins": How Authentication ...

Critical authentication bypass vulnerabilities in Fortinet FortiGate and related products (CVE-2025-59718 and CVE-2025-59719) are now under active attack, allowing "ghost" SSO logins that completely sidestep normal controls and logs. For Australian organisations, this is more than a VPN or firewall problem – it is a board-level exposure that directly tests whether your external penetration testing, internal penetration testing, and red team assessment services are capable of simulating SSO abuse, identity takeovers, and lateral movement across hybrid networks.

Fortinet "Ghost Logins": How Authentication Bypass Attacks Expose Gaps in Your Penetration Testing Strategy
Lean Security Expert
September 14, 2025

AI-Powered Red Teaming: Is Your Australian Business Ready for the New Threat Landscape?

Lean Security Expert
September 14, 2025
AI-Powered Red Teaming: Is Your Australian Business Ready for the New Threat Landscape?

Attackers are now weaponising AI to create faster and more evasive attacks, making traditional security playbooks obsolete. To defend against AI, you must use AI. We leverage adversarial AI and advanced red teaming to prepare your business for the next generation of sophisticated threats.

Comment
Lean Security Expert
September 12, 2025

Source Code Security Assessment in the Cloud: Benefits, Risks, and Best Practices

Lean Security Expert
September 12, 2025
Source Code Security Assessment in the Cloud: Benefits, Risks, and Best Practices

Protect your development pipeline with proactive scanning, expert reviews, seamless CI/CD integration, maximize security, and reduce risk with Source Code Security Assessment in the Cloud.

Comment
Lean Security Expert
September 8, 2025

The Future of Mobile App Security Testing in an API-Driven World

Lean Security Expert
September 8, 2025
The Future of Mobile App Security Testing in an API-Driven World

Secure your interconnected mobile and API ecosystems with proactive mobile application security testing, vulnerability scanning, and managed services to protect data and ensure regulatory compliance.

Comment
Lean Security Expert
September 5, 2025

How Managed Security Services Can Reduce Operational Costs Without Sacrificing Protection

Lean Security Expert
September 5, 2025
How Managed Security Services Can Reduce Operational Costs Without Sacrificing Protection

Cut security costs without cutting corners. Learn how managed security services deliver scalable, cost-effective protection that boosts ROI for businesses of all sizes.

Comment
Lean Security Expert
September 2, 2025

Beyond the Basics: Advanced Security Testing Techniques for 2025 Threats

Lean Security Expert
September 2, 2025
Beyond the Basics: Advanced Security Testing Techniques for 2025 Threats

Learn about the latest security testing techniques for 2025 threats, including AI-driven assessments, adaptive testing, and red teaming, to strengthen enterprise cyber defenses.

Comment
Lean Security Expert
August 29, 2025

WAFs Aren’t Enough: Why You Still Need a Web Application Scanning Strategy

Lean Security Expert
August 29, 2025
WAFs Aren’t Enough: Why You Still Need a Web Application Scanning Strategy

WAFs are not a complete security solution. Read this piece to learn why, even with a WAF-managed service, you still need a web application scanning strategy to stay protected.

Comment
Lean Security Expert
August 25, 2025

The True Cost of Skipping Website Penetration Testing

Lean Security Expert
August 25, 2025
The True Cost of Skipping Website Penetration Testing

Discover the financial, legal, and reputational risks of neglecting website penetration testing—and why every business needs a reliable penetration testing service in place.

Comment
Lean Security Expert
August 22, 2025

Managing Web Security Assessment for SaaS Platforms: A 2025 Guide

Lean Security Expert
August 22, 2025
Managing Web Security Assessment for SaaS Platforms: A 2025 Guide

Explore the best practices for managing web security assessment across SaaS platforms with 10 actionable strategies for identifying and resolving vulnerabilities in 2025.

Comment
Lean Security Expert
August 18, 2025

Cloud Infrastructure Testing: Why Your DevOps Pipeline Depends On It

Lean Security Expert
August 18, 2025
Cloud Infrastructure Testing: Why Your DevOps Pipeline Depends On It

Learn how to integrate cloud infrastructure testing into your DevOps pipeline without delays with 10 expert steps from Lean Security’s security testing services.

Comment
Lean Security Expert
August 15, 2025

From Open Source to Secure Code: How to Reduce Risk in Hybrid Dev Environments

Lean Security Expert
August 15, 2025
From Open Source to Secure Code: How to Reduce Risk in Hybrid Dev Environments

Learn how to secure hybrid development environments by highlighting open source software risks, conducting code reviews, and using penetration testing to reduce threats.

Comment
Newer Posts
Older Posts
Contact us for a quote
Back to Top
Lean Security, 81-83 Campbell Street, Surry Hills, NSW, 2010, Australia+61 (2) 8078 6952info@leansecurity.com.au

About Lean Security

We are a specialist cybersecurity firm based in Sydney, focusing on penetration testing. We partner with organisations across Australia, providing expert-led testing and clear, actionable reports. Our goal is to give you the clarity and confidence needed to secure your digital assets.

     
Useful Links
Home
Application penetration testing
Security source code assessment
Mobile application penetration testing
Infrastructure penetration testing
API web services penetration testing
Threat Modelling Service

Newsletter

We respect your privacy.

Thank you!

Contact Us

Phone: +61 (2) 8078 6952
Email: info@leansecurity.com.au

Monday - Friday from 9.00 am to 8.00 pm
Saturday from 10.00 am to 6.00 pm