Neo Security labs
Deep-dive stories from our engineers on cloud security, offensive research, hardware hacking, and the real incidents that shape how we secure our clients.
All posts
Hacker insights into business logic vulnerabilities
Pepijn van der Stap started hacking at 14 and never stopped thinking like both an engineer and an attacker. An interview about business logic vulnerabilities, why scanners miss them, and what realistic red teaming looks like.
DatHuis: a pentest that mostly proved what was already solid
Gray-box penetration test of a modern SaaS platform on AWS. We went in with an attacker's mindset and came out pleasantly surprised: the fundamentals were done right.
BlueHammer & RedSun: Windows Defender CVE-2026-33825 explained
A straight-faced breakdown of the Windows Defender zero-day (CVE-2026-33825) plus a concrete action plan for Dutch SOC and endpoint teams: patch status, detection content, compensating controls.
5-Dimensional AI prompting & shawarma: David's infosec internship
Swedish student David shares his journey from Gothenburg University to Neo Security in Amsterdam. From marketing transformation to dark web demos, discover how an internship abroad shaped his career.
Wouter's journey in security
Wouter is not your typical IT consultant. From Commodore 64 to DJ booth, and from XS4ALL to Korper - his story is one of passion, freedom and technology.
Why Erik Homma breaks ancient appliances just for science
From building a ZX-81 at eight years old to dissecting PLCs and tearing apart decades-old protocols and integrations until they behave. How a self-taught hardware hacker became a Senior Security Consultant at Neo Security.
EY data leak: 4TB backup exposed
How Neo Security discovered a 4TB SQL Server backup from Ernst & Young publicly exposed on Azure. A deep dive into cloud misconfigurations, attack surface management, and why responsible disclosure matters.
What we write about
Cloud & data exposure
Leaks, misconfigurations, and what happens when backups, databases or buckets end up on the public internet. Plus what you can do to find them first and prevent a repeat.
Incidents, response & recovery
Real stories from the field: how we report vulnerabilities, handle ransomware and breaches, recover data, and guide organisations through the full incident lifecycle.
Hardware & deep engineering
Hardware hacking, reverse engineering, legacy systems and the deep engineering mindset behind how we design and secure real-world infrastructure.
Want more stories like this?
We publish deep technical breakdowns, incident response war stories, and practical security guidance. No marketing fluff. Just engineers talking about what actually happened.