Anonymized real-world engagements showcasing how ZeroTrace PK identifies, exploits, and helps remediate critical security vulnerabilities across industries.
A leading fintech startup's digital wallet and payment gateway had critical security flaws that could have led to mass financial fraud and complete platform compromise.
The client was preparing for a Series A funding round and needed an independent third-party security audit to satisfy investor due diligence requirements. Their platform processed over $2M in monthly transactions through mobile and web applications, with 50,000+ active users. No prior security assessment had been conducted.
The administrative panel's two-factor authentication could be bypassed by manipulating the verification request, granting full admin access including user management, transaction controls, and system configuration.
Payment gateway API keys and database credentials were hard-coded in the mobile application's source code. Decompiling the APK revealed production secrets that could be used to initiate unauthorized transactions.
Insecure Direct Object References in the transfer API allowed any authenticated user to initiate transfers from other users' wallets by simply changing the wallet ID parameter — no additional authorization checks existed.
A regular user account could be escalated to admin privileges by modifying the role parameter during profile update. The server accepted client-side role changes without validation.
An unprotected API endpoint returned user objects including bcrypt password hashes, enabling offline brute-force attacks against user credentials at scale.
All 14 critical and high-severity findings were remediated within 3 weeks. ZeroTrace PK conducted a full retest confirming 100% closure. The client successfully passed investor due diligence and closed their Series A round. A recurring quarterly VAPT engagement was established.
A healthcare technology provider's patient management platform had critical security flaws exposing sensitive medical records and personally identifiable information of 50,000+ patients.
The client needed HIPAA compliance validation before onboarding a major hospital network. Their platform managed electronic health records (EHR), appointment scheduling, and prescription data for multiple clinics. A competitor had recently suffered a data breach, making security a top priority for their prospective client.
Patient records including full names, national ID numbers, phone numbers, medical history, and prescription data were publicly accessible through an unauthenticated API endpoint. No authentication or authorization was required to access any patient's complete medical file.
The mobile application's login flow could be bypassed entirely by replaying a modified authentication token. Once bypassed, the attacker had full access to the doctor's dashboard including all patient records under their care.
Patient data, session tokens, and doctor credentials were stored in plaintext on the mobile device in SharedPreferences (Android) and UserDefaults (iOS) — accessible to any app with root/jailbreak access or through device backups.
Medical imaging files (X-rays, lab reports, prescriptions) were stored in a publicly accessible S3 bucket with directory listing enabled. Over 120,000 files were exposed without any access controls.
All critical findings were escalated immediately with emergency remediation guidance. The client fixed all vulnerabilities within 2 weeks. ZeroTrace PK provided a HIPAA-aligned compliance report that helped the client successfully onboard the hospital network. Ongoing quarterly assessments were established to maintain compliance.
A rapidly growing SaaS company's REST API infrastructure had systemic authorization flaws that allowed cross-tenant data access — putting enterprise client data at risk.
The client was pursuing SOC 2 Type II certification and needed a comprehensive API penetration test as part of their compliance roadmap. Their platform served 200+ enterprise customers with multi-tenant architecture, processing sensitive business data including contracts, financial documents, and employee records. Their largest client had mandated an independent security audit as a contract renewal condition.
72 out of 120 API endpoints lacked proper tenant isolation checks. By modifying resource IDs in API requests, a user from Tenant A could read, modify, and delete data belonging to Tenant B — including confidential documents and user records.
The user update endpoint accepted unvalidated parameters. By including "role": "org_admin" in a profile update request, any team member could escalate themselves to organization administrator with full data access and user management capabilities.
A stored XSS vulnerability in the comments feature combined with missing CSRF protection on the email-change endpoint created a chained attack: a malicious comment could silently change a victim's email address and trigger a password reset — resulting in full account takeover.
Administrative API endpoints for billing management, user provisioning, and audit log access were not restricted to admin roles. Regular users could invoke admin-only functions by directly calling the endpoints.
JWT tokens had excessive lifetimes (30 days), lacked audience validation, and the signing key was a weak, guessable string. Token reuse after password change was also possible, meaning compromised sessions remained active indefinitely.
ZeroTrace PK worked closely with the client's engineering team over 4 weeks to implement a comprehensive authorization framework across all 120+ endpoints. All critical findings were remediated and verified through a full retest. The client achieved SOC 2 Type II certification, retained their largest enterprise customer, and now conducts bi-annual security assessments with ZeroTrace PK.
An internal and external network penetration test revealed multiple paths to compromise a regional bank's core banking infrastructure — from initial access to domain admin in under 4 hours.
The bank's regulatory body mandated an annual independent penetration test as part of PCI-DSS compliance. The scope covered external-facing infrastructure, internal network segments, Active Directory environment, and the internet banking web application. The bank had 1,200+ employees across 15 branches with a centralized IT infrastructure.
Starting from an unprivileged internal network position, our team achieved Domain Admin access within 4 hours through a chain of: LLMNR/NBT-NS poisoning → NTLMv2 hash capture → offline cracking → lateral movement → Kerberoasting → service account with DA privileges.
Multiple critical management interfaces (vCenter, firewall admin, database consoles) were accessible from the general employee network with default or weak credentials — no network segmentation between user and management zones.
The internet banking application's password reset flow was vulnerable to account enumeration and OTP brute-force. Combined with predictable session tokens, this allowed complete takeover of any customer's banking account.
The bank implemented network segmentation, hardened Active Directory configurations, deployed EDR solutions, and redesigned the internet banking authentication flow. ZeroTrace PK conducted a comprehensive retest after 6 weeks confirming all critical findings were resolved. The bank achieved PCI-DSS compliance and engaged ZeroTrace PK for annual assessments.
Every case study above started with a client who thought their systems were secure. Let ZeroTrace PK find your vulnerabilities before attackers do.
Get Free Assessment