Dunicot A cybersecurity consultancy and advisory firm.

Attack scenarios · 8 classes

How a vulnerability becomes a breach.

One page per vulnerability class: how the attack unfolds step by step, what it costs the business, how a tester confirms it, and the control that actually holds. These are representative scenarios rather than client engagements, so they describe the class rather than any one organisation's systems.

By vulnerability class

Critical · E-commerce and retail

SQL injection in e-commerce

SQL injection, or SQLi, can turn one unparameterised product filter into a read of every customer name, address, order and password hash. How to test for it.

High to Critical · Healthcare

Stored XSS account takeover

Stored XSS: text saved in a patient message field runs inside the clinician console, drives the staff session and reads every record that account can reach.

Critical · Insurance

Server-side request forgery

Server-side request forgery (SSRF) can turn a URL field into theft of a server's cloud credentials, and then every file in storage. How we test for it.

High to Critical · HR and payroll software

GraphQL introspection and batching

Introspection maps the GraphQL schema, a missing field authorisation check opens the records, and alias batching reads thousands of them in one POST.

Critical · Travel and hospitality

OAuth account takeover

A loose redirect_uri check leaks an OAuth code, letting an attacker take over an SSO account and reach the loyalty balance and passport data inside it.

Critical · Manufacturing

Kerberoasting to Domain Admin

Kerberoasting lets any authenticated domain user crack a service account password offline and reach Domain Admin, with no failed logons and no lockouts.

Critical (conditional) · Government and public sector

Dependency confusion

Dependency confusion lets an attacker register your internal package name on npm or PyPI, so the next build installs theirs and runs it on the build agent.

High · Telecommunications

Hardcoded keys in mobile apps

A production API key compiled into a published mobile app can be extracted from the build and replayed against the API directly, with no app and no account.

Which of these reaches your stack?

Scoping starts with what you actually run. A fixed quote follows a short call.