TL;DR Introduction In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow ...
TL;DR  How we ended up here  My colleague Adam Bromiley and I recently tripped over one of those ‘What!?’ findings. We could completely break an IT-OT segmentation without having to do … anything. We ...
Last year one of my colleagues, Ken, received the sad news that a father of a friend had passed away. He was a tech-savvy gentleman and had invested in smart tech to make his and his family’s life ...
On Tuesday 4 th August, 5 brave souls set off to the faraway climes of Nevada, bound for DEF CON 34. We had 9 cases of tech with us, a motley assortment of flight simulators, industrial control CTFs ...
UK Office. Pen Test Partners LLP, Unit 2, Verney Junction Business Park, Buckingham, MK18 2LB, United Kingdom +44 20 3095 0500 ...
Our Paul Brownridge will be presenting: In 30 minutes, access the building and takeover the domain. Mission Improbable? Follow a penetration tester through the key stages of an engagement, from ...
As Red Teamers, we often find information in SharePoint that can be useful for us in later attacks. As part of this we regularly want to download copies of the file, or parts of their contents. In ...
When researching lateral movement techniques I came across a post from Raphael Mudge (of Cobalt Strike fame). He details scripting an Aggressor Script for Matt Nelson’s MMC20.Application Lateral ...
Key relay attacks against keyless entry vehicles are well known. Many 3 rd party car alarm vendors market themselves as solutions to this. We have shown that fitting these alarms can make your vehicle ...
A few weeks back we read a story on the BBC web site about a BBC employee seeing someone else’s video footage on the mobile app for their home security camera. It wasn’t clear how this happened, but ...
When a data breach hits the news, it’s usually all about the numbers: millions of names, emails, and maybe even credit card details stolen. Sounds serious, right? But here’s the catch, sometimes *not ...