Cyberis Blog
Reassuringly clear thinking.
- Attack surface discovery
- Penetration testing
- Red teaming
AI Is Raising the Stakes: Why Security Basics Matter More Than Ever
AI is changing the economics of vulnerability discovery. As the barrier to finding and weaponising software flaws falls, organisations can no longer assume that fully patched systems and perimeter controls are enough. The fundamentals of good security - minimising attack surface, enforcing least privilege, segmenting environments, managing data properly and investing in detection - are becoming more important, not less.
- Penetration testing
- Red teaming
- Research
- Tools and techniques
Probabilistic Systems, Deterministic Security
LLMs and AI agents are increasingly being connected to tools, APIs, data sources and business workflows. While this creates real value, it also introduces an important security question: should probabilistic systems be trusted to enforce security boundaries? This article explains why prompts, refusals and LLM-based guardrails should not be treated as access controls. It explores the difference between deterministic security enforcement and probabilistic model behaviour, highlights risks seen in real-world AI agent testing, and sets out why secure LLM architectures should keep deterministic controls in charge of identity, authorisation, data access, tool execution and sensitive output handling. The key principle is simple: use LLMs at the interaction layer, but enforce security in the surrounding application, services and infrastructure.
- News
- Penetration testing
- Red teaming
- Research
- Tools and techniques
One Identity Secure Password Extension Privilege Escalation (CVE-2025-27582)
Cyberis has discovered a local privilege escalation (LPE) vulnerability - CVE-2025-27582 - in One Identity Secure Password Extension x64 v5.14.3.1, a component of One Identity Password Manager. By abusing the Password Self-Service feature available on the Windows lock screen, an attacker can bypass security restrictions, launch a SYSTEM-privileged print dialog, and ultimately gain a SYSTEM shell. This vulnerability requires only local access and is trivially exploitable in environments where this software is deployed. An attacker can escalate to SYSTEM directly from the logon screen—without requiring valid credentials.
- Detect and respond
- Red teaming
- Research
Microsoft Bookings – Facilitating Impersonation
Microsoft Bookings introduces a significant security risk by allowing end users to create fully functional Entra accounts without administrative oversight. These accounts, tied to shared Booking pages, can be exploited for impersonation, phishing, and email hijacking. Attackers could leverage this functionality to bypass security measures, gain unauthorised access to sensitive resources, and facilitate lateral movement within an organisation. Our blog explores these weaknesses in detail and provides recommendations for detection and mitigation.
- Red teaming
"Assumed Compromise" Assessments: A Guide
In red teaming, defining the business objectives of the exercise early is essential to driving the best value realisation from the exercise. Each attack simulation involves a bespoke scoping exercise, and it is during these scoping processes that we discuss different ways of potentially achieving the desirable business objectives and the pros and cons of each.
- Penetration testing
- Red teaming
- Tools and techniques
Avoiding Microsoft OneNote attachments spreading malware on your network
OneNote is note-taking software, developed by Microsoft and is included in the default Office suite bundle. In recent years, OneNote files have become popular channels for attackers to distribute malware, given their common installation and Microsoft's organisational measures to block macros from running in Excel and Word.
- Red teaming
Informed consent: Social engineering and 'assumed compromise'
"Informed consent: Permission granted in full knowledge of the possible consequences" We're familiar with the concept of informed consent; in medicine, we treat it as criminal to perform a medical intervention without valid informed consent being in place. In red teaming, informed consent is just as important.
- Penetration testing
- Red teaming
Why you need to protect DA (Domain Admin)
This post will discuss why protecting administrative accounts responsible for the domain and the forest is so important. We will look at what is means for an attacker to gain access to these privileges and the impact of these types of breaches.
Improve your security
Our experienced team will identify and address your most critical information security concerns.