Contact us: info@tenendo.com

A payment provider's pre-transaction AWS review looked clean — until we found a public Spring Boot Actuator endpoint leaking a heap dump with live credentials for a privileged production role. No exploit chain needed: just download, extract, and the cloud environment was ours. Here's why we don't separate AppSec from infrastructure testing, and w…
Tenendo specialists discovered an unattended staging environment and leveraged its vulnerabilities for sensitive information disclosure. This information was later reused in an attack against the main application, that allowed us access to the payment API on behalf of other customers of our Client.
Poor network segmentation enabled an attacker to pivot from internal access to full cloud takeover.