Minnesota Water Attacks and the Predictable Reality
How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares.
Lares tests web apps, APIs, mobile apps, thick clients, embedded systems, and AI-enabled workflows to expose the risks automation misses. We show you how attackers can abuse your applications and what to fix first.

Applications are where identity, data, and business logic meet, which is why attackers focus there. Lares brings operator-led testing to your application stack so you get a clear view of real abuse paths, not just a scanner report.
Auth, session handling, user flows, and business logic.
Auth, object-level access control, data exposure, and trust boundaries.
Local storage, transport security, auth flows, and app-API interactions.
Desktop and client-heavy apps where local logic and secrets create risk.
Applicaiton-layer behavior in connected devices and embedded systems.
LLM features, agents, and AI-driven workflows; deeper AI testing via the dedicated AI service when needed.
When limited source code or user credentials are provided, we conduct a Gray Box assessment, combining elements of black-box exploitation with inside knowledge.
The Approach: Engineers test the application from the perspective of an authenticated user (such as a standard employee, customer, or tenant).
The Focus: Identifying privilege escalation paths, tenant isolation bypasses, Insecure Direct Object References (IDOR), and broken access controls.
The Outcome: Clear visibility into what a malicious insider or compromised user account could achieve once past the initial login screen.
When source code is unavailable or you want to test your application from the perspective of an external attacker, we perform a full Black Box assessment.
The Approach: Our engineers attack the application with zero prior knowledge of the internal codebase or architecture, simulating a real-world threat actor.
The Focus: Identifying externally facing vulnerabilities, authentication bypasses, injection flaws, and business logic errors that a malicious user could exploit.
The Outcome: A realistic understanding of your application's external risk profile and resilience against unauthenticated attacks.
Having access to the source code provides the most sound and thorough approach to assessing application security during or after the development phase.
The Approach: A deep-dive review of the application's source code, architecture, and backend integrations, paired with targeted black-box and network testing.
The Focus: Uncovering deeply embedded design flaws, hardcoded credentials, insecure cryptographic implementations, and systemic vulnerabilities that external scans miss.
The Outcome: Complete remediation guidance at the code level, enabling your developers to build secure-by-design applications and eliminate technical debt.
We assess web applications, APIs, mobile apps, thick clients, embedded or IoT-connected interfaces, and AI-enabled application workflows when they are in scope. The goal is to test how the full application ecosystem can actually be abused, not just how one isolated component behaves.
Yes. Application security testing is focused on the application layer, including user flows, authentication, authorization, APIs, data handling, and business logic. Broader penetration testing can include infrastructure, hosts, and other enterprise assets beyond the application itself.
We use automation where it helps, but the real value comes from manual testing performed by operators who validate impact, chain weaknesses, and test abuse paths that scanners miss. That is especially important for business logic flaws and multi-step attack paths.
Yes. If those systems work together, we can scope them together so the assessment reflects how attackers would approach the real environment. This is often the best way to uncover issues that cross trust boundaries and application layers.
Yes. The right model depends on your goals, maturity, and available access. We scope the engagement around what you need to learn, whether that is external attacker realism, deeper validation, or release-focused assurance.
Yes. If your application includes LLM features, agents, or AI-driven workflows, we can test those as part of the application attack surface. For broader or deeper AI-specific validation, Lares also offers a dedicated AI Security Testing service.
Common findings include authentication and authorization failures, insecure API behavior, data exposure, input handling flaws, business logic abuse, and weaknesses caused by configuration or trust assumptions. In complex applications, smaller issues can often be chained into meaningful attack paths.
You receive an executive summary, a technical findings report, prioritized remediation guidance, and a debrief with the testing team. Retesting can also be included when you need validation that critical fixes were completed successfully.
Sometimes. Production testing can be appropriate when it is carefully scoped and coordinated, but many clients prefer staging or pre-production depending on risk tolerance and operational constraints.
If you want to validate whether a specific application or application ecosystem can be abused, AppSec is usually the right fit. If the concern is AI-specific behavior or autonomous workflows, AI testing may be the better option; if the goal is broader adversary simulation across multiple surfaces, red teaming is more appropriate.




