ADVERTISEMENT

Pentest tools left online are allowing hackers to exploit Fortune 500 firms

Hackers are exploiting intentionally vulnerable penetration testing and security training apps that have been mistakenly exposed to the public internet, giving them access to cloud environments including CloudFlare, F5, and Palo Alto Networks.

Red Team pentester

By Shutterstock

Ann-Marie Corvin
Ann-Marie Corvin Senior Journalist
January 22, 2026 3 min read
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News
Add us as your Preferred Source on Google.

Nearly 2,000 exposed training apps found online

ADVERTISEMENT
“What began as a harmless lab could lead directly to an organization’s crown jewels.”
Noam Yaffe, senior security researcher, Pentera
AWS-secrets-manager
Screenshot shows how researchers were able to access an account’s “secrets manager” service on AWS. Image by Pentera.

In-the-wild usage detected

“There is limited oversight of these applications, as any tests conducted on them could reveal vulnerabilities that teams may assume are intentional rather than malicious.”
Nivedita Murthy, senior security consultant, Black Duck

ADVERTISEMENT