Rhino Security Labs

Strategic Blog

Referral Beware, Your Rewards are Mine (Part 1)

Whit Taylor
August 27, 2025

Referral rewards programs are nearly ubiquitous today, from consumer tech to SaaS companies, but are rarely given much security oversight. In this blog post we’ll dig into the common technical implementations of rewards programs on…

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

CloudGoat: New Scenario and Walkthrough (sns_secrets)

CloudGoat Official Walkthrough Series: ‘glue_privesc’

John De Armas

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, glue_privesc. where you will attempt to move through an AWS…