Sanitized Assessment: Tier-1 European Digital Asset Custody & API Infrastructure
Vulnerabilities Uncovered During Initial Reconnaissance
Target Scope & Ingress Points
Scope comprised 14 public REST and WebSocket API microservices, external Kubernetes ingress clusters, and employee VPN concentrators operating under strict mutual non-disclosure constraints.
Simulated Attack Vector Chain
Luar Red Team leveraged a subtle JSON parser discrepancy between the edge gateway and internal Go services to bypass authentication headers, escalating to arbitrary database read queries via blind SQL injection in internal ledger endpoints.
Defensive Hardening Implemented
Applied automated AST-based query parameterization, enforced strict JSON schema validation at the Dublin edge WAF, and isolated database clusters in private WireGuard subnets. Zero regressions observed upon 48-hour re-test.