Contact us: info@tenendo.com

A payment provider's pre-transaction AWS review looked clean — until we found a public Spring Boot Actuator endpoint leaking a heap dump with live credentials for a privileged production role. No exploit chain needed: just download, extract, and the cloud environment was ours. Here's why we don't separate AppSec from infrastructure testing, and w…
The main goal of the Technical Audit from a customer request was to understand if the system is scalable or not and provide guidance for improvements.
The team created several hardware connect-back appliances and used it in a PCI DSS segmentation testing.
Do you want to know how your organisation will fare against an internal attack? Look no further than Tenendo's Internal Adversary Simulation.
Successful phishing attacks revealed detection gaps in support and SOC teams, allowing unauthorized access without alerts.
Weak authentication and poor segmentation enabled privilege escalation from VPN access to full domain control.
The Azure penetration test helped the client identify and remediate multiple issues and misconfigurations, harden their infrastructure and calculate potential risks.
Poor network segmentation enabled an attacker to pivot from internal access to full cloud takeover.
Poor network segmentation enabled an attacker to pivot from internal access to full cloud takeover.
Evaluating EDR Product against Threat Actors: Uncovering Limitations and Collaboration for Enhanced Detection of Multiple Killchains.