lateral-movement
6 posts
The breach was the network working as intended
The 2015 Polish S incident: lateral movement from inherited permissions and automated escalation, where access was granted by position not verified at use.
OpenSSH turns every authenticated session into a pivot
How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.
Every commit swipes your badge at the door
Commits execute under identities. Unenforced IAM boundaries turn routine development into unowned access grants. What failed, why, and what must change.
Your API breach was working as designed
API authentication failing at the request level is a trust boundary failure. Inadequate identity validation makes lateral movement a design outcome.
The door Mythos left unlocked
Mythos is an identity management failure. Privileged access boundaries were not enforced. Lateral movement reached sensitive data.
Q1 2026: Iranian crews living off P2P
Compromised P2P accounts are driving lateral movement and exfiltration in Israeli orgs. The fabric, not the platform, is the C2 channel.