Sign in

Pen Test Partners

@pentestpartners.bsky.social
143 followers 13 following 42 posts
PostsRepliesMedia
Reposted by Pen Test Partners
Happygeek @happygeek.bsky.social · 14/05/2025
By me @forbes.com: Accessing restricted SharePoint passwords using Copilot AI. Excellent work by @pentestpartners.bsky.social, Jack Barradell-Johns and @thekenmunroshow.bsky.social #infosec www.forbes.com/sites/daveyw...
forbes.com
New Warning — Microsoft Copilot AI Can Access Restricted Passwords
Red team hackers have accessed restricted passwords using Microsoft’s Copilot AI for SharePoint — here’s what you need to know.
052
Pen Test Partners @pentestpartners.bsky.social · 08/05/2025
Our #RedTeam came across a massive #SharePoint, too much to explore manually. So, with some careful prompting, they asked #Copilot to do the heavy lifting... It opened the door to credentials, internal docs, and more. 📌 www.pentestpartners.com/security-blo... #AIsecurity
The Microsoft sharepoint logo (teal shapes with an "S") has a text bubble saying: "That file is restricted!"
A human (with their face obscured) in a black hoodie (printed with: clichéd h4x0r) says: "Copilot, I really need those passwords"
The Microsoft copilot logo (a rainbow swirly shape) replies: "OK, here you go..."
011
Pen Test Partners @pentestpartners.bsky.social · 29/04/2025
🔐 Your passwords say more than you might think… In our latest blog post, Pedro Venda shares some of the surprising insights hiding behind the passwords we choose and why it matters for security. 📌 www.pentestpartners.com/security-blo...
010
Pen Test Partners @pentestpartners.bsky.social · 24/04/2025
We hosted an away day for the UK easyJet security team, sharing insights, collaborating and discussing all things aviation security. ✈️ #AviationSecurity #CyberSecurity #SecurityCollaboration #KnowledgeSharing #WorkingTogether #AviationInsights
010
Pen Test Partners @pentestpartners.bsky.social · 22/04/2025
We are exhibiting! 🚨   There’ll be live demos, discussions, and friendly faces...   Come see us at the RSA Conference 2025 in San Francisco. We are at booth S-2144 in the South Expo from April 28th to May 1st.   ➡️ www.pentestpartners.com/event/rsa-co...   #RSAC2025 #RSAC #CyberSecurity #InfoSec
000
Pen Test Partners @pentestpartners.bsky.social · 17/04/2025
Is your phone secretly listening to you? Well… yes But not how you might think, Ken Munro explains... youtube.com/shorts/Y9KZu...
youtube.com
Is your phone secretly listening to you? Well… yes
YouTube video by Pen Test Partners
000
Pen Test Partners @pentestpartners.bsky.social · 15/04/2025
Data breaches usually make the headlines because of the sheer volume of data. However, research shows that often the volume of data is falsely inflated. So, how do forensics experts tell what’s real and what’s noise? read here: www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 14/04/2025
Sometimes you just can’t beat being in the same room. We’ve just wrapped up another round of co-working days across the UK, including London, Buckingham, Birmingham, Sheffield, Cardiff, Edinburgh, and Portsmouth. A great chance for our team to meet up, share ideas, and collaborate. #HybridWork
010
Pen Test Partners @pentestpartners.bsky.social · 09/04/2025
Using your work email for personal use may seem convenient, but it can put your company at risk. 🚫 If that third-party site gets breached, corporate credentials could fall into the wrong hands. For further details and tips for businesses to limit this risk: www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 08/04/2025
Last week, Ken Munro and Jo Dalton were in Munich for Aerospace Tech Week. Ken Munro was talking about hacking electronic flight bags and the importance of security vulnerability disclosure in aerospace ✈️…
000
Pen Test Partners @pentestpartners.bsky.social · 03/04/2025
From August 1, 2025, any wireless device sold in the EU will need to meet stricter cybersecurity requirements under the Radio Equipment Directive (RED). We’ve broken down what this means and how to get ready in our latest blog post: www.pentestpartners.com/security-blo...
010
Pen Test Partners @pentestpartners.bsky.social · 01/04/2025
Last week @thekenmunroshow.bsky.social presented at the EEMUA Conference 2025, looking at cyber security challenges shared between maritime and industrial systems in his talk, "Marine cyber security – plain sailing or a rough passage?"
001
Pen Test Partners @pentestpartners.bsky.social · 31/03/2025
Released by Intel in 1998, IPMI is a hardware management interface operating independently of the OS. Our latest blog post by Kieran looks at INTEL IPMI vulnerabilities and how to mitigate them ➡️ www.pentestpartners.com/security-blo...
030
Pen Test Partners @pentestpartners.bsky.social · 25/03/2025
Our Sam Macdonald presented a talk on dealing with imposter syndrome at BSides Kent last weekend.   #BSidesKent #CyberCommunity #BSides #MentalHealth #ImposterSyndrome #Conference
021
Pen Test Partners @pentestpartners.bsky.social · 24/03/2025
If your organisation suffers a cyber incident, what you do next will determine the outcome. Our latest blog post is a practical playbook for the first 24 hours after a cyber incident... Read the blog post and our checklist here: www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 20/03/2025
@thekenmunroshow.bsky.social presented at the Maritime Cyber Guild 2025 meet up in Copenhagen, talking all things shipping with some photos of the Network Ferret himself, Andrew Tierney. 🚢 #maritimecybersecurity #maritimesecurity #cybersecurity #infosec #maritimesafety
010
Pen Test Partners @pentestpartners.bsky.social · 19/03/2025
Benefiting newbies, experts, and everyone in between, cybersecurity community groups are an excellent way to network and learn 💻 ... Our latest blog post by Nick Simpson looks at how you can find UK groups, including OWASP, DEF CON groups, 2600 and more: www.pentestpartners.com/security-blo...
002
Pen Test Partners @pentestpartners.bsky.social · 14/03/2025
Our Warren Houghton is back at it again with Nerding Out with Viktor. Warren shares fascinating insights into how he successfully infiltrates secure spaces and bypasses sophisticated defences.   Watch the full episode here: vpetersson.com/podcast/S02E...
021
Pen Test Partners @pentestpartners.bsky.social · 12/03/2025
In our latest blog post, Kieran Larking highlights that the No-cache directive does not prevent caching and looks at typical caching behaviour directives and how to correctly use these directives to balance performance and security: www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 06/03/2025
Looking to become a Cyber Essentials assessor? In our latest blog post, Ekom Ibiok shares his journey to becoming a Cyber Essentials and Cyber Essentials Plus assessor with insights to help you on your own path: www.pentestpartners.com/security-blo...
030
Pen Test Partners @pentestpartners.bsky.social · 04/03/2025
Your DNS security can accidentally leak your entire subdomain structure. DNSSEC with NSEC/NSEC3 records is great for ensuring integrity and authentication but can be a sneaky way for attackers to ‘zone walk’ and enumerate your domains... www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 03/03/2025
Last week Ken Munro and Matt Dowson were in Dublin, Ireland, for the IATA World Data Symposium. We presented a talk covering some of the significant legacy cybersecurity risks in aviation systems. #AviationCybersecurity #IATAWDS #LegacySystems #AviationSafety #CyberThreats
030
Pen Test Partners @pentestpartners.bsky.social · 28/02/2025
There are new mandatory United States Coast Guard cyber regulations for US flagged vessels and ports that come into effect on July 16. Be prepared. Full details and advice here: www.pentestpartners.com/security-blo... #USCG #cyberregulations #maritimesecurity #cybercompliance #cyberawareness
001
Pen Test Partners @pentestpartners.bsky.social · 26/02/2025
In our latest blog, David Lodge looks at the Rockchip boot process. He covers the boot order and how to force the MCU into low-level modes for direct USB access, as well as essential tools like xrock and rkflashtool: www.pentestpartners.com/security-blo...
020
Pen Test Partners @pentestpartners.bsky.social · 24/02/2025
Ken Munro recently presented at BCS The Chartered Institute of IT with an evening on hacking various transport systems, including planes, trains, automobiles, and ships…
020
Pen Test Partners @pentestpartners.bsky.social · 21/02/2025
In aviation, cybersecurity is not optional. The industry recognises that ensuring safety requires a consistent, standardised approach. Alex Lomas explains the process of conducting avionics penetration tests, looking at each stage in line with ED-203A: 👉 www.pentestpartners.com/security-blo...
021
Pen Test Partners @pentestpartners.bsky.social · 07/02/2025
We got curious about cheap, tiny phones promoted to children on social media, so we bought a few to see what’s inside... Read our blog on this here: www.pentestpartners.com/security-blo... #CyberSecurity #DigitalSafety
youtube.com
Security Flaws Found in Tiny Phones Promoted to Children
YouTube video by Pen Test Partners
021
Pen Test Partners @pentestpartners.bsky.social · 03/02/2025
In 2016, the first strain of Mirai distributed DDoS attacks against Twitter, Facebook, and KrebsOnSecurity. Initially, it was misunderstood as an IoT botnet. However, our reverse engineering revealed that it targeted digital video recorder software from a single vendor: youtu.be/5gYN
youtu.be
The Mirai DVR botnet that took down Twitter and Facebook explained...
YouTube video by Pen Test Partners
000
Pen Test Partners @pentestpartners.bsky.social · 28/01/2025
We revisited wearable device forensics to show how someone could gain unauthorised access to a Garmin smartwatch and expose your data such as activity logs, GPS data, sleep patterns, and device information: www.pentestpartners.com/security-blo...
021
Pen Test Partners @pentestpartners.bsky.social · 24/01/2025
Maritime cybersecurity isn’t just for large fleets—small operators face risks too. Complying with security standards can feel daunting, but it’s important to protect your systems and data from attack. Read here: www.pentestpartners.com/security-blo...
002
Pen Test Partners @pentestpartners.bsky.social · 21/01/2025
How can we protect the integrity and confidentiality of the footage from body-worn cameras in law enforcement? Alex Lomas has outlined how encryption, integrity verification, and security measures can protect these devices so that the footage remains reliable www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 20/01/2025
Our investigation back in 2018 revealed how a flaw in Swann's cameras exposed private video feeds! Sadly, we still find similar flaws in products today... www.youtube.com/watch?v=uZX9... #CyberSecurity #IoTSecurity #SmartHome #Privacy
youtube.com
How We Hacked Swann Cameras: Lessons for IoT Security
YouTube video by Pen Test Partners
020
Pen Test Partners @pentestpartners.bsky.social · 15/01/2025
We got curious about cheap, tiny phones promoted to children on social media, so we bought a few to see what’s inside. What did we find? Alarming security issues that parents need to know about: www.pentestpartners.com/security-blo... #CyberSecurity #CyberAwareness #GadgetSafety #TechNews
020
Pen Test Partners @pentestpartners.bsky.social · 07/01/2025
When the dust settles after a cyber breach, the spotlight is on tech fixes. But what about the other aspects that can make or break your recovery? These 10 actions go beyond tech fixes to protect your future resilience, reputation, and relationships. 👉 www.pentestpartners.com/security-blo...
011
Pen Test Partners @pentestpartners.bsky.social · 03/01/2025
CVRs are crucial for aviation safety, capturing cockpit audio for investigations.  But there's a twist... they have an erase button.   It sounds counterintuitive, right? But there's more to this... www.pentestpartners.com/security-blo...
032
Reposted by Pen Test Partners
Cyber House Party @cyberhouseparty.bsky.social · 30/12/2024
Even DJs need downtime! 🎧 Throwback to summer when Don1 became El Hombre at The Fox for CHP & @pentestpartners.bsky.social . 🇪🇸✨ Spanish vibes, epic tunes, and good times. Turn it up, dream of 2025! 🪩❤️ #CyberHouseParty www.mixcloud.com/CyberHousePa... @don1.bsky.social
mixcloud.com
This Is What We Do - Dec 24 Ft Don1
043
Pen Test Partners @pentestpartners.bsky.social · 24/12/2024
Wishing you and your loved ones a wonderful festive season from all of us at PTP. 🎄 A heartfelt thank you to our people, clients, partners, and followers for an incredible 2024. Here’s to a safe, joyful holiday season and a secure 2025! #TechUnderTheTree #MerryChristmas #HappyHolidays
010
Pen Test Partners @pentestpartners.bsky.social · 18/12/2024
Explore the challenges, regulations, and real-world lessons in IoT security through Ken Munro's talk at the PCI SSC Europe Community Meeting. Has IoT security truly improved? Watch now: www.youtube.com/watch?v=hae8... #IoTSecurity #CyberSecurity #PCI #IoTRegulations #CyberThreats #InfoSec
010
Pen Test Partners @pentestpartners.bsky.social · 11/12/2024
In our latest blog, "How easily access cards can be cloned and why your physical access control systems (PACS) might be vulnerable," Warren reveals how attackers exploit outdated configurations and default encryption keys to bypass these systems: www.pentestpartners.com/security-blo...
011
Pen Test Partners @pentestpartners.bsky.social · 09/12/2024
Your building's PACS can be vulnerable to card cloning. Our Warren recently shocked security professionals by cloning a badge in minutes, right before their eyes. His blog post covers five checks to help prevent cloning: www.pentestpartners.com/security-blo...
012
Pen Test Partners @pentestpartners.bsky.social · 05/12/2024
Secure boot ensures only authentic firmware can run on a device and should form part of a layered defence strategy. But is it enough to only have a secure boot on your main processor? What about sub-systems without secure boot capabilities? 🤔 www.pentestpartners.com/security-blo...
002
Pen Test Partners @pentestpartners.bsky.social · 03/12/2024
What would you do in a breach? 🚨   When attackers strike, technical defences aren’t all that matters. Non-technical preparations can make a big difference.   🔗 Read Luke Davis’s blog for six key steps you’ll wish you’d taken before a breach: www.pentestpartners.com/security-blo...
000
Pen Test Partners @pentestpartners.bsky.social · 27/11/2024
Phishing attacks are getting smarter, but that doesn’t mean you can’t stay one step ahead. In the final part of Rachel Rabin’s blog series, you’ll find practical advice on spotting and stopping email threats in Microsoft 365. Check it out here: www.pentestpartners.com/security-blo...
011
Pen Test Partners @pentestpartners.bsky.social · 19/11/2024
Our latest blog goes into the shocking £12 million rental scam featured on UNTOLD. We partnered with Channel 4 to uncover...🔎 Fake documents, stolen identities, and advanced social engineering - Read the full story: www.pentestpartners.com/security-blo...
033