Financial clearing house
External assessment, authorized
- 25 exposed hosts mapped from the outside.
- Video-surveillance, FortiVPN, managed-file-transfer and OPSWAT administrative portals were reachable from the internet; the MFA portal lacked lockout.
- A payment site meant for a private network was exposed publicly.
- Version-matched vulnerabilities included GoAnywhere CVE-2024-0204 and Umbraco CVE-2025-24012 / CVE-2025-24011, alongside SQL injection on a public endpoint. A version match alone is not proven exploitation.
Anonymized, selected engagement.





