Fortbridge

Fortbridge FORTBRIDGE โ€“ Leading IT Security Services in London | Cybersecurity, Pe*******on Testing, Red Teaming and Cloud Security

FORTBRIDGE โ€“ Leading IT Security Services in London | Cybersecurity Solutions, Pe*******on Testing, Red Teaming, Network & Cloud Security, and Cyber Defense

2025 in review at FORTBRIDGEA year of original security research, community, and sharing knowledge - across three contin...
22/01/2026

2025 in review at FORTBRIDGE

A year of original security research, community, and sharing knowledge - across three continents.

๐—›๐—ถ๐—ด๐—ต๐—น๐—ถ๐—ด๐—ต๐˜๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต
This year we published and presented three original research projects , including:

โ€ข ๐—™๐—ฒ๐—ฒ๐—น๐—ฑ ๐—ฑ๐—ฎ๐˜๐—ถ๐—ป๐—ด ๐—ฎ๐—ฝ๐—ฝ - critical issues exposing highly sensitive user data
โ€ข ๐—ฉ๐—ฒ๐˜€๐˜๐—ฎ ๐—”๐—ฑ๐—บ๐—ถ๐—ป ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ผ๐˜ƒ๐—ฒ๐—ฟ - exploiting reduced seed entropy in bash RANDOM to achieve full control panel compromise
โ€ข ๐—–๐—ผ๐—ป๐—ฐ๐—ฟ๐—ฒ๐˜๐—ฒ ๐—–๐— ๐—ฆ: Two races, one RCE - two race conditions leading to remote code ex*****on.

Our work on Vesta was also nominated for ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฆ๐˜„๐—ถ๐—ด๐—ด๐—ฒ๐—ฟ ๐—ง๐—ผ๐—ฝ ๐Ÿญ๐Ÿฌ ๐—ช๐—ฒ๐—ฏ ๐—›๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—พ๐˜‚๐—ฒ๐˜€ ๐—ผ๐—ณ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ, which weโ€™re particularly proud of.

Our work was also covered by The Guardian and The Register, helping bring responsible security research into the mainstream.

๐—–๐—ผ๐—ป๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ๐˜€ & ๐—ฐ๐—ผ๐—บ๐—บ๐˜‚๐—ป๐—ถ๐˜๐˜†
We had the chance to present our research across the US, Canada, Europe, and Asia including:

โ€ข ๐—˜๐˜‚๐—ฟ๐—ผ๐—ฝ๐—ฒ: APIDays London, BSides Kent, BSides Bournemouth, BSides Bristol, SteelCon & DotNetSheff (Sheffield), BSides Budapest, BSides Dresden, BSides Galway, Pass the SALT Lille, Owasp Porto
โ€ข ๐—ก๐—ผ๐—ฟ๐˜๐—ต ๐—”๐—บ๐—ฒ๐—ฟ๐—ถ๐—ฐ๐—ฎ: BSides Calgary, HackMiami, DEF CON 33 (Las Vegas)
โ€ข ๐— ๐—ถ๐—ฑ๐—ฑ๐—น๐—ฒ ๐—˜๐—ฎ๐˜€๐˜: BlueHat (Tel Aviv)

๐—š๐—ถ๐˜ƒ๐—ถ๐—ป๐—ด ๐—ฏ๐—ฎ๐—ฐ๐—ธ & ๐—š๐—ฟ๐—ผ๐˜„๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—ป๐—ฒ๐˜…๐˜ ๐—ด๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป
We worked with ๐˜๐—ต๐—ฟ๐—ฒ๐—ฒ ๐—ถ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐˜€ this year, focusing on hands-on offensive security, real-world tooling, and research workflows.

As part of giving back to the community, we also sponsored BSides Dresden, supporting independent, community-driven security events in Europe.

Thanks to everyone who attended our talks, asked tough questions, reviewed our research, or collaborated with us along the way - and to the organisations who trusted us with responsible disclosure and remediation.

Looking forward to building on this in 2026.
โ€”
FORTBRIDGE

*******ontesting

๐ŸŒŽ North America Cybersecurity Tour: May 2025 โ€“ Letโ€™s Connect! ๐ŸŒŽWeโ€™re excited to share that our very own Bogdan Tiron  wi...
28/04/2025

๐ŸŒŽ North America Cybersecurity Tour: May 2025 โ€“ Letโ€™s Connect! ๐ŸŒŽ

Weโ€™re excited to share that our very own Bogdan Tiron will be speaking at Bsides Calgary (May 1โ€“2) and Hack Miami (May 17), presenting his latest research: "๐—˜๐˜…๐—ฎ๐—บ๐—ถ๐—ป๐—ถ๐—ป๐—ด ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ถ๐—ป ๐—š๐—ฟ๐—ฎ๐—ฝ๐—ต๐—ค๐—Ÿ โ€“ ๐—” ๐—™๐—ฒ๐—ฒ๐—น๐—ฑ ๐—–๐—ฎ๐˜€๐—ฒ ๐—ฆ๐˜๐˜‚๐—ฑ๐˜†."

As part of the tour, Bogdan will be traveling across Canada and the US, and is looking forward to meeting fellow security professionals, CISOs, and AppSec leaders for coffee, tech chats, or networking:

๐Ÿ”น ๐—–๐—ฎ๐—น๐—ด๐—ฎ๐—ฟ๐˜† โ€“ Apr 30 to May 4 (speaking at BSides Calgary on May 1โ€“2)
๐Ÿ”น ๐—ฆ๐—ฒ๐—ฎ๐˜๐˜๐—น๐—ฒ โ€“ May 4 to May 8
๐Ÿ”น ๐——๐—ฒ๐˜๐—ฟ๐—ผ๐—ถ๐˜ โ€“ May 8 to May 11 (attending BSides Detroit)
๐Ÿ”น ๐—ช๐—ฎ๐˜€๐—ต๐—ถ๐—ป๐—ด๐˜๐—ผ๐—ป ๐——๐—– โ€“ May 11 to May 14
๐Ÿ”น ๐— ๐—ถ๐—ฎ๐—บ๐—ถ โ€“ May 14 to May 18 (speaking at HackMiami on May 17)

If you're based in any of these cities and would like to discuss securing modern applications, pentesting, phishing, red teaming, or hear more about our Feeld security research (featured in The Guardian and The Register), feel free to reach out โ€” we'd love to connect!



Looking forward to connecting with many of you along the way! ๐Ÿ’ฅ

We've been diving deep into what we learned from Zero Point Security's RTO and RTO II training โ€” and decided to put that...
03/04/2025

We've been diving deep into what we learned from
Zero Point Security's RTO and RTO II training โ€” and decided to put that knowledge to use.

๐Ÿ’ก The result? A custom variant of the Sliver C2 framework built to fly under the radar, bypassing Windows Defender and Elastic EDR with minimal code edits.

This was part of a hands-on research project developed by our brilliant intern, Samuel Birkinshaw.

The results speak for themselves.

๐Ÿงช Check it out:
๐Ÿ”— https://fortbridge.co.uk/research/reforging-sliver-how-simple-code-edits-can-outmaneuver-edr/

Learn how sliver can help you bypass EDR with tailored adaptations and discover the benefits of open source security tools.

We're excited to announce that Adrian Tiron will be speaking at BlueHat IL, organized by Microsoft! Adrian will start by...
03/04/2025

We're excited to announce that Adrian Tiron will be speaking at BlueHat IL, organized by Microsoft!

Adrian will start by poking at the PHP-based web interface of Vesta Control Panel โ€” then take a detour into PHP internals (C) and bash source (also C) to understand how weak entropy in $RANDOM can lead to full admin takeover. From there, heโ€™ll walk through the custom exploit logic โ€” mixing in a bit of Rust and Python to bring it to life.

Join us in celebrating his innovative research and connecting with fellow cybersecurity professionals at BlueHat IL!

๐Ÿฑ The cat is out of the bag! ๐ŸฑBogdan Tiron and Adrian Tiron will be speaking at BSidesBUD - IT Security Conference in Ma...
03/04/2025

๐Ÿฑ The cat is out of the bag! ๐Ÿฑ

Bogdan Tiron and Adrian Tiron will be speaking at BSidesBUD - IT Security Conference in May!

Once again, FORTBRIDGE has two presentations at a BSides conferenceโ€”continuing our tradition of delivering cutting-edge cybersecurity insights to the community.

This isn't the first time we've brought multiple talks to BSides, and it certainly won't be the last. Stay tuned for more details on what weโ€™ll be presenting!

Looking forward to seeing you in Budapest! ๐Ÿ‡ญ๐Ÿ‡บ

The UK Telecoms Security Act (TSA) is a crucial regulation aimed at strengthening the security of telecom networks again...
03/04/2025

The UK Telecoms Security Act (TSA) is a crucial regulation aimed at strengthening the security of telecom networks against ever-evolving cyber threats.

Tier 2 operators must be fully compliant by March 31, 2025โ€”is your organization prepared?

In our latest blog post, we cover:

โœ… The purpose, scope, and key requirements of the TSA
โœ… Compliance challenges, and penalties for non-compliance
โœ… The vital role of pe*******on testing in securing telecom networks
โœ… How businesses can align with regulatory frameworks

๐Ÿ”— Read the full blog post to stay ahead of compliance and enhance your telecom security:
https://fortbridge.co.uk/regulations/pentesting-for-uk-telecoms-security-act/

Learn about the UK Telecoms Security Act and how pe*******on testing helps ensure compliance and strengthen telecom network security.

This past weekend, Adrian Tiron had an amazing time speaking at BSides Kent, and it was truly an unforgettable experienc...
03/04/2025

This past weekend, Adrian Tiron had an amazing time speaking at BSides Kent, and it was truly an unforgettable experience. Engaging with such a passionate audience, exchanging ideas, and diving deep into cybersecurity discussions made it all the more rewarding.

A huge shoutout to his fellow speakersโ€”Stephan Berger, Joshua Limbrey, Donato Capitella, Sam Macdonald, Sadiyah Saeed, Jason R.C. Nurse, Bisola Kayode CISSP, CISM, Clare Patterson, Santi Abastante, and Lorna A.โ€” it was a privilege to share the stage with such brilliant minds delivering thought-provoking talks.

A massive thank you to the BSides Kent organizersโ€”Jason Steer, James Spear, and Lucy M.โ€”for making this event possible. Your hard work and dedication to the cybersecurity community do not go unnoticed!

And to everyone who attended โ€” thank you for the great questions, conversations, and good vibes throughout the day. Events like these are a reminder of why I love being part of this community.

Many thanks to everyone who reached out, asked questions, or simply wanted to connect and chat โ€” it was a real pleasure interacting with you all! The event totally exceeded our expectations.

Already looking forward to the next one!

This past weekend, Bogdan Tiron had the privilege of speaking at BSides Galway, where he shared insights on API security...
03/04/2025

This past weekend, Bogdan Tiron had the privilege of speaking at BSides Galway, where he shared insights on API security and access control vulnerabilities from our research at FORTBRIDGE. It was an incredible experience discussing real-world risks and engaging with such a knowledgeable audience.

We were pleasantly surprised by the level of interest and curiosity from the attendees as he received a lot of great questions at the end of his talk about law, privacy, logs, pentesting, REST/GraphQL, and more. Itโ€™s always exciting to see such enthusiasm for cybersecurity!

A huge thank you to everyone who attended, asked questions, and shared their thoughts. Your support and feedback made this session truly rewarding! ๐Ÿ™Œ

Special thanks to Scott Thomas and Tom Hickey for organizing such a fantastic event and to all the volunteers who helped make BSides Galway a success. Your hard work and dedication truly made a difference!

Looking forward to more insightful conversations in the cybersecurity community!

With cyber threats on the rise and data breaches making headlines, organizations must strengthen their security measures...
03/04/2025

With cyber threats on the rise and data breaches making headlines, organizations must strengthen their security measures to meet regulatory requirements. The HITRUST CSF provides a unified framework for managing security and compliance, but achieving certification requires more than just policiesโ€”it demands proactive testing.

In this blog post, we break down HITRUST CSF, its key requirements, challenges, and how pe*******on testing plays a crucial role in achieving compliance. Plus, we explore the penalties for non-compliance and the future of HITRUST CSF.

๐Ÿ” Read the full blog post here:

https://fortbridge.co.uk/regulations/why-pe*******on-testing-is-critical-for-hitrust-csf-compliance/

Learn how HITRUST CSF and pentesting strengthen cybersecurity and ensure compliance, safeguarding your organization's sensitive data.

๐Ÿšจ ๐—ง๐—ต๐—ฒ ๐——๐—ถ๐—ด๐—ถ๐˜๐—ฎ๐—น ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ฅ๐—ฒ๐˜€๐—ถ๐—น๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—”๐—ฐ๐˜ (๐——๐—ข๐—ฅ๐—”) ๐—–๐—ผ๐—บ๐—ฒ๐˜€ ๐—ถ๐—ป๐˜๐—ผ ๐—™๐—ผ๐—ฟ๐—ฐ๐—ฒ ๐—ง๐—ผ๐—ฑ๐—ฎ๐˜†! ๐ŸšจToday marks a significant milestone for cyberse...
03/04/2025

๐Ÿšจ ๐—ง๐—ต๐—ฒ ๐——๐—ถ๐—ด๐—ถ๐˜๐—ฎ๐—น ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ฅ๐—ฒ๐˜€๐—ถ๐—น๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—”๐—ฐ๐˜ (๐——๐—ข๐—ฅ๐—”) ๐—–๐—ผ๐—บ๐—ฒ๐˜€ ๐—ถ๐—ป๐˜๐—ผ ๐—™๐—ผ๐—ฟ๐—ฐ๐—ฒ ๐—ง๐—ผ๐—ฑ๐—ฎ๐˜†! ๐Ÿšจ

Today marks a significant milestone for cybersecurity and operational resilience across the EU. With DORA officially in effect, organizations must now align their digital operations with robust resilience practices to mitigate cyber risks effectively.

To help you navigate these changes, weโ€™ve published an insightful blog post: "๐—จ๐—ป๐—ฑ๐—ฒ๐—ฟ๐˜€๐˜๐—ฎ๐—ป๐—ฑ๐—ถ๐—ป๐—ด ๐——๐—ข๐—ฅ๐—”: ๐—œ๐—บ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ณ๐—ผ๐—ฟ ๐—ฃ๐—ฒ๐—ป๐—ฒ๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฒ๐˜€".

๐—ง๐—ต๐—ถ๐˜€ ๐—ฝ๐—ผ๐˜€๐˜ ๐—ฐ๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐˜€:

โœ… Companies in scope
โœ… Pe*******on testing requirements, including Threat-Led Pe*******on Testing (TLPT)
โœ… Testing frequency and guidelines
โœ… Internal vs. external testers
โœ… ICT third-party risk management

Whether youโ€™re a financial entity or an ICT service provider, this blog post will guide you through DORAโ€™s key provisions, ensuring compliance and a stronger cybersecurity posture.

๐Ÿ”— ๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐—น๐—น ๐—ฎ๐—ฟ๐˜๐—ถ๐—ฐ๐—น๐—ฒ ๐—ต๐—ฒ๐—ฟ๐—ฒ:
https://fortbridge.co.uk/regulations/understanding-dora-implications-for-pe*******on-testing-practices/

Stay informed. Stay resilient. Letโ€™s embrace the new era of operational resilience together!

Explore the Digital Operational Resilience Act (DORA) and its pivotal impact on pe*******on testing in the EU financial sector.

๐ŸŒ ๐—ฃ๐—ฒ๐—ป๐—ฒ๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ณ๐—ผ๐—ฟ ๐—œ๐—ฆ๐—ข/๐—œ๐—˜๐—– ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ: ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—จ๐—น๐˜๐—ถ๐—บ๐—ฎ๐˜๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—š๐˜‚๐—ถ๐—ฑ๐—ฒIn a world where cyber threats are ever-evolving,...
03/04/2025

๐ŸŒ ๐—ฃ๐—ฒ๐—ป๐—ฒ๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ณ๐—ผ๐—ฟ ๐—œ๐—ฆ๐—ข/๐—œ๐—˜๐—– ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ: ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—จ๐—น๐˜๐—ถ๐—บ๐—ฎ๐˜๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—š๐˜‚๐—ถ๐—ฑ๐—ฒ

In a world where cyber threats are ever-evolving, securing sensitive information isnโ€™t just a priorityโ€”itโ€™s a necessity. ISO/IEC 27001 provides a globally recognized framework to protect your organizationโ€™s valuable data, enhance trust, and ensure regulatory compliance.

๐—ข๐˜‚๐—ฟ ๐—น๐—ฎ๐˜๐—ฒ๐˜€๐˜ ๐—ฏ๐—น๐—ผ๐—ด ๐—ฝ๐—ผ๐˜€๐˜ ๐—ฑ๐—ถ๐˜ƒ๐—ฒ๐˜€ ๐—ฑ๐—ฒ๐—ฒ๐—ฝ ๐—ถ๐—ป๐˜๐—ผ:

โœ… What ISO/IEC 27001 is and why it matters
โœ… The certification process and compliance requirements
โœ… The critical role of pe*******on testing in fortifying your ISMS
โœ… Future trends and best practices for resilience

Whether you're just starting your compliance journey or looking to strengthen your security posture, this guide has everything you need.

๐Ÿ”— ๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐—น๐—น ๐—ฏ๐—น๐—ผ๐—ด ๐—ฝ๐—ผ๐˜€๐˜ ๐—ต๐—ฒ๐—ฟ๐—ฒ:

https://fortbridge.co.uk/regulations/pe*******on-testing-for-iso-iec-27001-a-detailed-guide-to-compliance/

๐Ÿ‘‰ Donโ€™t let security be an afterthought. Learn how to stay ahead in todayโ€™s cyber landscape!

Discover everything you need to know about ISO/IEC 27001, from its purpose and implementation to its role in enhancing cybersecurity and achieving compliance.

Address

London
SE135FR

Opening Hours

Monday 9am - 6pm

Alerts

Be the first to know and let us send you an email when Fortbridge posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share