Blog

Research and field notes on AI security, penetration testing and offensive security from the Ironbark Cyber team.

Shadow IT Discovery: Finding the Systems Nobody Approved

Shadow IT Discovery: Finding the Systems Nobody Approved

Shadow IT, the SaaS, cloud and dev environments nobody approved, is a common source of breaches. Here's why it accumulates and how to find yours.

Vishing and Smishing: Phone and SMS Attacks Explained

Vishing and Smishing: Phone and SMS Attacks Explained

Vishing and smishing attacks target your help desk and MFA. How phone and SMS pretexts, MFA-reset abuse and MFA fatigue work, and how to harden your processes.

Assumed Breach Testing Explained: What Happens After the Phish

Assumed Breach Testing Explained: What Happens After the Phish

Assumed breach testing shows what an attacker can do after the first phish lands. What it is, how it differs from external testing, and why it matters.

Web Application Penetration Testing Methodology: A Full Guide

Web Application Penetration Testing Methodology: A Full Guide

A practical web application penetration testing methodology: recon, authentication, access control, business logic, injection and reporting, step by step.

GraphQL Security Testing: Common Vulnerabilities and How to Test

GraphQL Security Testing: Common Vulnerabilities and How to Test

GraphQL security explained: introspection exposure, query depth abuse, batching attacks and field-level authorisation, plus how to test for each.

Leaked Credentials: How to Check Exposure and Respond

Leaked Credentials: How to Check Exposure and Respond

Leaked credentials turn up in breaches, stealer logs, pastes and public repos. Here's how to check whether yours are exposed and what to do about it.

The Essential Eight Explained for Australian Organisations

The Essential Eight Explained for Australian Organisations

The ACSC Essential Eight explained: the eight mitigation strategies, the four maturity levels, who must comply and how testing proves your controls work.

Bug Bounty vs Penetration Testing: Which Do You Need?

Bug Bounty vs Penetration Testing: Which Do You Need?

Bug bounty vs penetration testing: what each is good at, where each falls short, and why mature security programs run both instead of choosing one.

Red Team vs Penetration Test: What's the Difference?

Red Team vs Penetration Test: What's the Difference?

Red team vs penetration test: how they differ in scope, goals, duration and cost, and how to work out which one your organisation should buy.

Common AWS Security Misconfigurations That Cause Breaches

Common AWS Security Misconfigurations That Cause Breaches

The AWS security misconfigurations that actually cause breaches: public S3 buckets, over-privileged IAM, exposed snapshots, metadata abuse and flat networks.

Put this into practice

A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.