Hackers exploit security testing apps to breach Fortune 500 firms
21 January 2026 at 15:00
Threat actors are exploiting misconfiguredΒ web applications used for security training and internal penetration testing, such as DVWA, OWASP Juice Shop, Hackazon, and bWAPP, to gainΒ access to cloud environments of Fortune 500 companies and security vendors. [...]