Keys to the Kingdom – Gaining access to the Physical Facility through Internal Access


This is a story of network segmentation and the impact that seemingly trivial misconfigurations can have for your organization. This is one of those occasions.

This particular pen test asked for goals-based assessment focusing on post-compromise activities — an attempt by the client to discover how vulnerable internal systems were to lateral movement by an attacker who had compromised the domain. Among the goals was a request to attempt to compromise the client’s Amazon Web Services (AWS) infrastructure and a secondary request to access and exploit any systems discovered to contain sensitive or critical operational data .

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • Poland to receive new European Union’s SAFE loans programme to boost cyber defence among other capabilities

    September 9, 2025

    Poland will receive EUR 43.7 billion in low-interest loans from the European Union’s new SAFE programme to boost defence capabilities, Deputy Prime Minister and Defence Minister Władysław Kosiniak-Kamysz said on Tuesday, confirming earlier reports. Calling the decision “a historic success,” Kosiniak-Kamysz said the funds will guarantee continued investment in Poland’s security and defence, including air and ...

  • Germany: Cyber Security in Road Transport 2025

    September 8, 2025

    Information technology has been part of modern vehicles for a long time already: connected services, AI-based assistants and over-the-air updates are standard in many vehicle models – and with autonomous driving functions the complexity grows further. Cyber security is of essential importance for these technologies. The publication offers a compact overview of the main challenges and ...

  • An Earth-Shattering Kaboom: Bringing a Physical ICS Penetration Testing Environment to Life (Part 2)

    September 2, 2025

    This is the second in a three-part series on building and using a testing bench for Industrial Control Systems (ICS). In this series, Rapi7 researchers will build a physical test bench, review program logic to find flaws, perform manual exploitation of commonly used ICS protocols such as Modbus, then develop malware to automatically exploit the bench ...

  • WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware

    August 29, 2025

    WhatsApp said on Friday that it fixed a security bug in its iOS and Mac apps that was being used to stealthily hack into the Apple devices of “specific targeted users.” The Meta-owned messaging app giant said in its security advisory that it fixed the vulnerability, known officially as CVE-2025-55177, which was used alongside a separate ...

  • Free webinar exploring the future of cyber security in critical industries

    August 28, 2025

    On 5 September 2025, cyber security professionals and industry leaders will gather online for a free, expert-led webinar: “Securing systems, data, and people: What are cyber security experts’ concerns for the future?”. This session serves as a precursor to the IET’s Cyber Security for Critical Industries Conference 2025, offering attendees a valuable glimpse into the ...

  • Jamaica: Cyber attack on Office of Registrar General contained, but services impacted

    August 27, 2025

    The Office of the Registrar-General (ORG), formerly the Registrar General’s Department (RGD), says it was affected by a cyber incident detected on Sunday and is working to determine its full scope. “Our initial assessment indicates that this incident was primarily designed to disrupt the availability of our systems,” the ORG said Wednesday. “As investigations are still ...