Purple Teaming

Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026)

Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026) 1672 941 Andrew Heller
What the Rockstar Games security incidents teach defenders about phishing-resistant MFA, SaaS token risk, internal segmentation, and data exfiltration detection. read more

Minnesota Water Attacks and the Predictable Reality

Minnesota Water Attacks and the Predictable Reality 1200 630 Andrew Heller
How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares. read more

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical 1672 941 Andrew Heller
Point-in-time pen tests can’t catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case. read more

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat 1672 941 Andrew Heller
Claude models attacked real infrastructure while believing they were in a simulation. Anthropic’s retrospective reveals a new AI risk class beyond alignment. read more

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout 1672 941 Andrew Heller
OpenAI’s frontier model escaped its sandbox and breached Hugging Face’s cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS. read more

Pentesting 101 – Part 1: So, you need or want a Pentest

Pentesting 101 – Part 1: So, you need or want a Pentest 615 584 Lares Labs
Unsure where to start with penetration testing? Our Pentesting 101 guide breaks down what penetration testing actually is, the differences between vulnerability scanning and pentesting, and the various types of assessments available to help you find the right fit for your organization. read more

Advanced Techniques of Infiltrating Fortune 100 Companies

Advanced Techniques of Infiltrating Fortune 100 Companies 1200 630 Lares Labs
In the high-stakes world of enterprise cybersecurity, even the most fortified defenses can be breached. This whitepaper provides a technical deep dive into the advanced methodologies—including OSINT, MFA fatigue, and lateral movement—used by Lares adversarial engineers to test and harden Fortune 100 security postures against sophisticated real-world threats. read more

The Lowdown on Lateral Movement

The Lowdown on Lateral Movement 1200 630 Lares Labs
Defenders think in lists, but attackers think in graphs. In this post, the Lares Labs team breaks down the mechanics of lateral movement and explores how you can leverage Symmetrical Task Framing to outmaneuver threat actors navigating your network. read more

What We Look For in a Penetration Tester at Lares (And Why Clients Care)

What We Look For in a Penetration Tester at Lares (And Why Clients Care) 1200 630 Andrew Heller
What is the difference between a standard security report and a true adversarial assessment? It all comes down to the operators. See what we look for at Lares. read more

WEBINAR: Stop Guessing, Start Proving: Why You Should Combine TTX and TTP Replay

WEBINAR: Stop Guessing, Start Proving: Why You Should Combine TTX and TTP Replay 150 150 Andrew Heller
Watch our Lares webinar to learn why combining Tabletop Exercises (TTX) with TTP Replay is the ultimate win-win for evidence-backed security testing. read more

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.