RC RANDOM CHAOS

lateral-movement

6 posts

The breach was the network working as intended
Article

The breach was the network working as intended

The 2015 Polish S incident: lateral movement from inherited permissions and automated escalation, where access was granted by position not verified at use.

OpenSSH turns every authenticated session into a pivot
Article

OpenSSH turns every authenticated session into a pivot

How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.

Every commit swipes your badge at the door
Article

Every commit swipes your badge at the door

Commits execute under identities. Unenforced IAM boundaries turn routine development into unowned access grants. What failed, why, and what must change.

Your API breach was working as designed
Article

Your API breach was working as designed

API authentication failing at the request level is a trust boundary failure. Inadequate identity validation makes lateral movement a design outcome.

The door Mythos left unlocked
Article

The door Mythos left unlocked

Mythos is an identity management failure. Privileged access boundaries were not enforced. Lateral movement reached sensitive data.

Q1 2026: Iranian crews living off P2P
Article

Q1 2026: Iranian crews living off P2P

Compromised P2P accounts are driving lateral movement and exfiltration in Israeli orgs. The fabric, not the platform, is the C2 channel.