Rhino Security Labs

Strategic Blog

Referral Beware, Your Rewards are Mine (Part 1)

Whit Taylor
August 27, 2025

Referral rewards programs are nearly ubiquitous today, from consumer tech to SaaS companies, but are rarely given much security oversight. In this blog post we’ll dig into the common technical implementations of rewards programs on…

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

CloudGoat: New Scenario and Walkthrough (sns_secrets)

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

Tyler Ramsbey

During research on the Vestaboard web platform, the Rhino research team identified three instances of Broken Access Controls.

Read-Access to other Vestaboards. 
Ability to update names of other users. 
Privilege escalation from Admin to…