Skip to content
Raxis
  • Home
  • Services
      Core Services
    • Raxis Red Team
    • AI Augmented Penetration Testing
    • Penetration Testing as a Service (PTaaS)
    • Elite Cybersecurity Services
    • Raxis listed as a Sample Vendor for Penetration Testing as a Service in two Gartner® Hype Cycle™, 2024 reports
    • Penetration Testing
    • Penetration Testing Services
    • Web Application Penetration Testing
    • API Security
    • Salesforce Applications
    • Internal Networks, Cloud, and VPC
    • External Networks and Internet
    • Wireless Networks
    • Mobile Applications
    • CyberSecurity Services
    • Compliance: PCI, HIPAA, GLBA, and more
    • Attack Surface Management
    • Breach and Attack Simulation
    • Cybersecurity Code Review
    • Cybersecurity Red Team
    • Phishing and Spear Phishing
    • Social Engineering
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Credit Card Industry (PCI)
    • Education
    • Finance and Banking
    • GLBA Safeguards Rule
    • Government Agencies
    • Healthcare (HIPAA)
    • Manufacturing
    • SOC 2
    • Technology
    • Technology and Software Development
    • Blockchain and Cryptocurrency
    • Media and Entertainment
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Careers
    • Meet Our Team
    • Signup for Raxis News
    • Resources
    • The Exploit Blog
    • Become a Raxis Partner
    • Certifications
    • Raxis One
    • Transporter Remote Pentesting
    • About Ethical Hacking
    • An Inside Look at a Raxis Red Team
    • Red, Blue, and Purple Teams
    • Penetration Test Glossary
    • What is a Penetration Test?
    • What is Web Application Penetration Testing?
  • The Exploit Blog
  • About Us
Contact Raxis Login
Raxis
Contact RaxisIcon Link to Contact Raxis
  • Home
  • Services
      Core Services
    • Raxis Red Team
    • AI Augmented Penetration Testing
    • Penetration Testing as a Service (PTaaS)
    • Elite Cybersecurity Services
    • Raxis listed as a Sample Vendor for Penetration Testing as a Service in two Gartner® Hype Cycle™, 2024 reports
    • Penetration Testing
    • Penetration Testing Services
    • Web Application Penetration Testing
    • API Security
    • Salesforce Applications
    • Internal Networks, Cloud, and VPC
    • External Networks and Internet
    • Wireless Networks
    • Mobile Applications
    • CyberSecurity Services
    • Compliance: PCI, HIPAA, GLBA, and more
    • Attack Surface Management
    • Breach and Attack Simulation
    • Cybersecurity Code Review
    • Cybersecurity Red Team
    • Phishing and Spear Phishing
    • Social Engineering
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Credit Card Industry (PCI)
    • Education
    • Finance and Banking
    • GLBA Safeguards Rule
    • Government Agencies
    • Healthcare (HIPAA)
    • Manufacturing
    • SOC 2
    • Technology
    • Technology and Software Development
    • Blockchain and Cryptocurrency
    • Media and Entertainment
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Careers
    • Meet Our Team
    • Signup for Raxis News
    • Resources
    • The Exploit Blog
    • Become a Raxis Partner
    • Certifications
    • Raxis One
    • Transporter Remote Pentesting
    • About Ethical Hacking
    • An Inside Look at a Raxis Red Team
    • Red, Blue, and Purple Teams
    • Penetration Test Glossary
    • What is a Penetration Test?
    • What is Web Application Penetration Testing?
  • The Exploit Blog
  • About Us
The Exploit Blog

Raxis Cybersecurity Insights From The Frontlines

bjager

Brice can be reached by contacting us.

AI-Augmented Series: LLM-Aided Enumeration for Dormant WordPress Account Discovery

AI-Augmented Series: LLM-Aided Enumeration for Dormant WordPress Account Discovery

By Ryan Chaplin
Posted in AI
Ryan Chaplin leads off our Augmented-AI series with a scenario from a recent pentest using AI to write a script to discover an account to gain system access.
TagsAi, AI-augmented, Cybersecurity Leadership, Penetration Testing
The @ctrl/tinycolor NPM Attack

The @ctrl/tinycolor NPM Attack: The Brutal Anatomy of a Cascading Supply Chain Breach

By Brian Tant
Posted in AI, In The News
Over 40 major packages were exploited in this malware campaign. Learn what happened and what your organization should do if you have been affected.
TagsAi, Supply Chain Attack
Why We Don’t Change Risk Ratings on Pentest Findings (Even When You Ask Nicely)

Why We Don’t Change Risk Ratings on Pentest Findings (Even When You Ask Nicely)

By Tim Semchenko
Posted in Penetration Testing, Security Recommendations
Raxis’ Tim Semchenko explains why we can’t lower risk ratings for your penetration test findings just because you ask and why that’s a good thing.
TagsMitigating Factors, Risk Rating
PSE & Red Team Series: Badge Cloning

PSE & Red Team Series: Badge Cloning

By Nathan Anderson
Posted in How To, Red Team, Social Engineering
Lead Penetration Tester Nathan Anderson is back with more PSE and red team advice, this time looking into three tools he uses to clone badges and gain access.
TagsBadge Cloning, Flipper Zero, Keysy, Proxmark3, RFID Card, Unleashed Firmware
Windows Kills Common Offline/Account-less Install Method

Windows Kills Common Offline/Account-less Install Method

By Ryan Chaplin
Posted in In The News, Networks
Microsoft Windows recently announced the removal of local-only installs on Windows 11. Raxis’ Ryan Chaplin looks at concerns and possible options.
Salesforce Compromise: What You Need to Know

Salesforce Compromise: What You Need to Know

By Jason Taylor
Posted in Exploits, In The News, Phishing, Security Recommendations
The FBI has released information to help organizations that are affected by recent attacks against Salesforce. Raxis’ Jason Taylor sums up next steps here.
TagsFBI, Salesforce
SpamGPT: Protecting Your Company From Large-Scale Phishing

SpamGPT: Protecting Your Company From Large-Scale Phishing

By Nathan Anderson
Posted in In The News, Phishing, Social Engineering
SpamGPT, a complex phishing and social engineering suite has made the news recently. Learn what it is and how organizations can protect their employees.
TagsAwareness, MFA, Phishing, Simulations
Cool Tools Series: Kerbrute

Cool Tools Series: Kerbrute

By Andrew Trexler
Posted in Exploits, Networks, Penetration Testing, Red Team
Raxis Principal Penetration Tester Andrew Trexler walks through the many uses of Kerbrute from user enumeration to brute-forcing and password spraying.
TagsActive Directory, Ad, Brute-Force, Kerbrute, Password Spraying, User Enumeration
Copilot Coming Soon to a Desktop Near You

Microsoft Copilot Coming Soon to a Desktop Near You

By Jason Taylor
Posted in In The News, Security Recommendations
With Microsoft automatically installing Copilot on Windows systems with Microsoft 365 desktop apps installed, organizations will want to set up AI policies.
Tags365, Ai, Copilot, Microsoft
Lateral Movement: From Beachhead to Breach

Lateral Movement: From Beachhead to Breach

By Nate Jernigan
Posted in Exploits, How To, Networks, Penetration Testing, Security Recommendations
Raxis Senior Penetration Tester Nate Jernigan discusses lateral movement in penetration testing and the methods and tools he uses when performing these attacks.
TagsBloodhound, Chisel, Intrusion Detection, Lateral Movement, Mimikatz, Network Segmentation, Penetration Testing, Principal of Least Privilege, SSH
Lessons from the DaVita Healthcare Ransomware Attack

Lessons from the DaVita Healthcare Ransomware Attack

By Brian Tant
Posted in In The News, Networks, Penetration Testing, Security Recommendations, Social Engineering
The DaVita ransomware attack is one of the most impactful recent healthcare breaches. Learn what happened and what could have been done to limit the impact.
TagsAwareness Training, Breach, Lateral Movement, Penetration Test, Phishing, Privilege Escalation, PTaaS, Ransomware, Spear Phishing
HTTP/1.1 Security News: What You Can Do Now

HTTP/1.1 Security News: What You Can Do Now

By Jason Taylor
Posted in Blog, In The News, Web Apps
A recent Portswigger white paper on HTTP/1.1 highlights critical security issues. If you use old products that still require it, here’s what you can do.
TagsHTTP 1.1, HTTP 2, HTTP Desync Attacks, Portswigger, Request Smuggling, WAF

2870 Peachtree Road
Suite #915-8924
Atlanta, GA 30305 USA

Contact us online

About Raxis

  • About Raxis
  • Careers
  • Terms and Conditions
  • Privacy Policy
  • Partners, Apply Here

Resources

  • The Exploit
  • Transporter Remote Penetration Testing
  • Penetration Test Glossary
  • What is a Penetration Test?
Facebook X Instagram Linkedin YouTube