The Vilkas Wire

Insights and field notes from real-world penetration tests and security research by the experts at Vilkas.

Latest Posts

Showing 19 of 19 total posts

 Why You Should Secure AD CS Against ESC1 (and How to Do It)

Why You Should Secure AD CS Against ESC1 (and How to Do It)

A misconfigured AD CS template (ESC1) can let any domain user escalate to Domain Admin in minutes. Learn how this common flaw works and the…

Oct 9, 20254 min read
Read Post
Legacy Firewalls, Modern Bootkits: Lessons from the Cisco VPN Zero-Days

Legacy Firewalls, Modern Bootkits: Lessons from the Cisco VPN Zero-Days

Cisco’s zero-day firewall flaws forced global emergency action. Here’s what leaders must know about the growing risk of aging, unsupported…

Sep 30, 20255 min read
Read Post
Active Directory Certificate Services: The Overlooked Weak Link (ESC1, ESC4, ESC8)

Active Directory Certificate Services: The Overlooked Weak Link (ESC1, ESC4, ESC8)

Misconfigured Active Directory Certificate Services (AD CS) can turn a minor foothold into a full domain compromise. Learn the top three…

Sep 25, 20255 min read
Read Post
Why "No Findings" Doesn't Mean No Value in Penetration Testing

Why "No Findings" Doesn't Mean No Value in Penetration Testing

A zero findings report can be useless or a powerful validation of your defenses. Here’s how to make sure it highlights security wins and…

Sep 23, 20255 min read
Read Post
Pentesting in 2025: Beyond the Numbers, Into the Real Risks

Pentesting in 2025: Beyond the Numbers, Into the Real Risks

Description: Pentesting in 2025 isn’t about stats or checklists. It’s about finding the real gaps that attackers still use, before they…

Sep 18, 20253 min read
Read Post
Active Directory Flaws That Still Break Security in 2025

Active Directory Flaws That Still Break Security in 2025

Stop AD attacks before they start. Our 2025 pentests keep uncovering the same 10 flaws. See which ones and how to lock them down before…

Sep 16, 20256 min read
Read Post
10 Essential Questions Every Cybersecurity Leader Must Ask

10 Essential Questions Every Cybersecurity Leader Must Ask

Cyber attackers thrive on uncertainty. If your cybersecurity leadership team can’t answer these 10 critical questions, your organization…

Sep 11, 20256 min read
Read Post

Want to Contribute?

Whether you're breaking down a recent pentest or reflecting on a red team engagement, we welcome your insights. Share your tactics, lessons learned, and perspectives with the community.

Learn How to Contribute