Key Takeaways
- The attack surface isn’t fixed. It changes in both directions: old assets nobody decommissioned, and new ones nobody has assessed yet.
- A forgotten legacy server or an old, unrotated credential can matter more than any current vulnerability.
- New tools adopted outside formal IT processes create real risk before anyone’s had the chance to test them.
- A scoped assessment only covers what existed on the day it ran. Everything added or forgotten since is untested.
- Continuous, credential-free exposure discovery is the only way to keep pace with an environment that never stops changing.
On this page
Nothing Stays Scoped: What This Month’s Attacks Reveal
Your last red team engagement was thorough. It covered every system you gave the testers access to. It found real issues, and your team fixed them.
But your environment didn’t stop there. A legacy server stayed online. An old integration credential was never rotated. A new AI tool went live without anyone logging it.
None of that was in scope. All of it was still part of your attack surface.
This month’s cases show what happens when attackers find the parts of your environment your last test never saw.
Case 1: Oracle Cloud Classic
Source: BleepingComputer, Security Boulevard, The Register
- A legacy “Oracle Cloud Classic” server, old infrastructure rebadged from an earlier product generation, had gone unpatched for years
- Attackers exploited a known Java vulnerability, one Oracle had patched back in 2022, that had simply never been applied to this older system
- A web shell and malware were installed, giving persistent access to Oracle’s Identity Manager database
- Usernames, hashed passwords, and single sign-on credentials were stolen, affecting more than 140,000 Oracle Cloud tenants
- Oracle initially denied any breach had occurred, before confirming the incident weeks later
Implication: Nobody was actively testing this server. It wasn’t new, it wasn’t interesting, and it wasn’t in anyone’s current scope. That’s exactly why it was still vulnerable to a fix that shipped years earlier.
Case 2: The Klue Breach
Source: TechCrunch, SecurityWeek, TheHackerNews
- Klue, a competitive intelligence platform, issued an integration credential in 2022 for a limited pilot project
- The credential was never rotated, reviewed, or retired. It stayed active for four years
- An extortion group found it and used it to generate access tokens linked to hundreds of customers’ Salesforce accounts
- Roughly 200 companies had data exposed, including security vendors LastPass, BeyondTrust, Snyk, Tanium, and HackerOne
- A near-identical pattern hit over 700 organisations the previous year through a different vendor’s integration, showing this is a repeating failure, not a one-off
Implication: A credential from a pilot project that ended years ago became the master key into hundreds of companies. No one was reviewing something that old, because nobody was still thinking about it.
Case 3: JadePuffer & The Langflow Server
Source: BleepingComputer, CSO Online, Dark Reading
- A Langflow server, a popular tool for building AI applications, was exposed to the internet, likely without formal security review
- Attackers exploited a known vulnerability in Langflow to gain code execution on the server
- From there, an autonomous AI agent took over the intrusion, harvesting credentials and pivoting to a separate production database
- The agent encrypted over 1,300 records before deleting the originals, adapting to failures along the way with no human direction
Implication: This wasn’t old, forgotten infrastructure. It was the opposite: a tool spun up recently enough that no assessment had ever touched it.
Key Patterns Across This Month’s Attacks
Three cases. Some assets were forgotten, others were brand new. Both were missed.
- No environment stays fixed. Assets are added and forgotten constantly, in both directions.
- Old assets fall out of scope over time. Legacy servers and stale credentials stop being reviewed long before they’re actually decommissioned.
- New assets fall outside scope from the start. Tools adopted quickly, often outside formal IT processes, go live before any review cycle reaches them.
- None of this was exotic. A known Java flaw. An unrotated access token. A documented Langflow bug. Nothing here needed a zero-day.
- A snapshot cannot protect a moving target. All three of this month’s breaches happened in the gap between what was tested and what the environment had become.
Why This Matters for Enterprise Security Leaders
Most enterprise security programmes validate their environment through scoped, point-in-time assessments:
These are valuable, and they answer a clear question. How secure is the environment we tested, on the day we tested it?
They don’t answer a different, more important question. How secure is the environment right now, months after that test ended?
A scoped assessment can only test what it’s told about. If a legacy server isn’t flagged, it isn’t tested. If a credential from a 2022 pilot isn’t mentioned, it isn’t reviewed. If a new AI tool goes live the week after the engagement ends, it’s invisible to the report entirely.
Consider what that means against the cases above:
- A network penetration test run against Oracle’s current production environment would likely have missed a rebadged legacy server nobody thought to include in scope.
- A vendor risk review conducted when Klue was first onboarded in 2022 would have looked fine. It had no reason to catch a credential that was only forgotten years later.
- Nothing about a fixed assessment window could have caught a Langflow server that didn’t exist yet when the last web application penetration test ran.
The result is a blind spot that grows with time. The longer it’s been since your last assessment, the bigger the gap between what was tested and what’s there.
How WRAITH Addresses This
The answer isn’t testing more often. It’s testing continuously, without needing to be told what to test.
WRAITH includes WISPr, a capability that continuously discovers what’s externally exposed across an organisation, without requiring input, credentials, or a defined scope from the customer. It looks for exactly the kind of asset a scoped assessment would miss: cloud resources, exposed services, forgotten domains, and misconfigurations that appeared after the last formal review.
Because WISPr runs continuously rather than at a fixed point in time, any new exposure it identifies can be folded straight into a live campaign. A legacy server coming back online, a new AI tool appearing on the perimeter, or a forgotten integration nobody remembers configuring all become visible as they appear, not months later at the next scheduled test.
This is the same problem all three of this month’s cases share. Old assets don’t announce that they’re still there. New ones don’t wait for permission. WRAITH is built to catch both, continuously, rather than relying on someone remembering to mention them.
A scoped assessment tests what you tell it about. WRAITH tests what’s actually there.
Jennifer Goulbourne
Jennifer is a Digital Marketing Executive at OmniCyber Security, where she's responsible for engaging the company's existing customer base across digital channels and creating helpful resources on threat intelligence and security operations for cybersecurity professionals and business leaders.