We call them success stories since it wasn't too late
Qasaba revealed critical issues that went unnoticed despite regular auditing, penetration testing, and vulnerability assessments — from individual organizations to entire national sectors.
Exposed Development Environment
A development environment had been exposed to the public network, just before the planned release of a mobile application. We managed to identify it and report instantly — before it could be discovered by adversaries.
Vulnerable CMS Plugin
A vulnerable plugin was found in the Content Management System of a medical company, on a machine that was regularly scanned and checked during penetration tests. The existing tools had missed it entirely.
Data Leak Discovery
Archives containing technical documentation and configuration backups were discovered on a single machine of a large network operator. The finding was reported immediately and fixed within two hours.
Unauthorized Services
A number of services operated privately by former employees were detected in the infrastructure of a company processing sensitive personal data. These shadow services represented a significant compliance and security risk.
Infected Machine
A server infected by malware was successfully identified and reported — an issue that was not discovered by the antivirus agent running on the machine.
Vulnerable Web Application
A critical issue in a project management system was identified — not reported previously by vulnerability assessment tools — enabling anyone to access confidential information.
Nationwide Sector Assessment
An entire country's public services infrastructure — healthcare, schools, hospitals, public utilities — was assessed in a single 24-hour discovery cycle. A large number of critical security issues were identified and the results were shared with the relevant stakeholders.
Third-Party Risk in Banking Sector
A critical third-party supply chain weakness was identified that would affect the entire banking sector in a country. Research preparation took 15 minutes, execution 8 hours, and analysis 2 hours. The findings were coordinated by financial sector authorities and the issue was addressed within 48 hours.