Contact us: info@tenendo.com

A payment provider's pre-transaction AWS review looked clean — until we found a public Spring Boot Actuator endpoint leaking a heap dump with live credentials for a privileged production role. No exploit chain needed: just download, extract, and the cloud environment was ours. Here's why we don't separate AppSec from infrastructure testing, and w…
This case is a very good example why manual penetration tests are valuable - the team achieved compromise without administrator access to the application, not using any known exploits or discovering injection/deserialization/other RCE flaws.