A forgotten test system can be a production entry point
Test systems are built quickly, with weak credentials, real data and nobody watching, and then never turned off.
They are frequently connected to the same networks and sometimes to the same databases as production. An attacker does not care that a machine is labelled test; they care that it is reachable, unpatched and holds a credential that works elsewhere. The label describes an intention, not an isolation boundary.
More on Attack surface management
- The Internet sees what you expose, not what your CMDB remembersCounted three. Answering six
- A new subdomain can create a new perimeterThe fence just got longer
- Shadow IT becomes shadow attack surfaceDoors around the back
- Acquisitions merge attack surfaces before inventoriesThe wire arrives first
- Internet exposure is a property that changesThe tide does not read your map
- Third-party hosted assets still carry your nameTheir building, your name over the door
