Rhino Security Labs

Strategic & Technical Blog

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

John De Armas
December 3, 2024

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, sqs_flag_shop. where you will attempt to move through an AWS…

CloudGoat: New Scenario and Walkthrough (sns_secrets)

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

CVE-2024-2389:
Command Injection Vulnerability
In Progress Flowmon

David Yesland

After our initial research into other Progress products we decided to take a look at another Progress product, Flowmon. This led to the discovery of an unauthenticated command injection vulnerability, which when coupled with a privilege…