Critical Security Incident
Upon departure of the former System Administrator, the organization's infrastructure was found in a state of advanced decay, with critical vulnerabilities enabling full system takeover in under 4 hours.
Cleartext Credentials
Passwords stored in plaintext in .creds.txt file
Privileged Container
Docker running with --privileged and host socket
Dirty COW Kernel Vuln
CVE-2016-5195 enabling root privilege escalation
Unencrypted Traffic
Internal API communications without TLS
Missing API Logging
No audit trail for API access patterns
Outdated Dependencies
Multiple packages with known CVEs