Neo Security labs
Diepgaande verhalen van onze engineers over cloudbeveiliging, offensief onderzoek, hardware hacking en de echte incidenten die bepalen hoe we onze klanten beveiligen.
Alle posts
Hacker insights into business logic vulnerabilities
Pepijn van der Stap started hacking at 14 and never stopped thinking like both an engineer and an attacker. An interview about business logic vulnerabilities, why scanners miss them, and what realistic red teaming looks like.
DatHuis: een pentest die vooral liet zien wat er al goed stond
Gray-box penetratietest van een modern SaaS-platform op AWS. We gingen naar binnen met de blik van een aanvaller en kwamen naar buiten aangenaam verrast: de fundamenten stonden goed.
BlueHammer & RedSun: Windows Defender CVE-2026-33825 explained
A straight-faced breakdown of the Windows Defender zero-day (CVE-2026-33825) plus a concrete action plan for Dutch SOC and endpoint teams: patch status, detection content, compensating controls.
5-Dimensional AI prompting & shawarma: David's infosec internship
Swedish student David shares his journey from Gothenburg University to Neo Security in Amsterdam. From marketing transformation to dark web demos, discover how an internship abroad shaped his career.
Wouter's journey in security
Wouter is not your typical IT consultant. From Commodore 64 to DJ booth, and from XS4ALL to Korper - his story is one of passion, freedom and technology.
Why Erik Homma breaks ancient appliances just for science
From building a ZX-81 at eight years old to dissecting PLCs and tearing apart decades-old protocols and integrations until they behave. How a self-taught hardware hacker became a Senior Security Consultant at Neo Security.
EY data leak: 4TB backup exposed
How Neo Security discovered a 4TB SQL Server backup from Ernst & Young publicly exposed on Azure. A deep dive into cloud misconfigurations, attack surface management, and why responsible disclosure matters.
Waar we over schrijven
Cloud & data exposure
Lekken, misconfiguraties en wat er gebeurt als back-ups, databases of buckets op het openbare internet belanden - plus wat u kunt doen om ze als eerste te vinden en herhaling te voorkomen.
Incidenten, respons & herstel
Echte verhalen uit de praktijk: hoe we kwetsbaarheden melden, omgaan met ransomware en datalekken, gegevens herstellen en organisaties begeleiden door de volledige levenscyclus van een incident.
Hardware & deep engineering
Hardware hacking, reverse engineering, legacy-systemen en de diepe technische mentaliteit achter hoe we echte infrastructuur ontwerpen en beveiligen.