An exposed credential in a web application may seem like a problem limited to development, but when combined with excessive permissions and targeting flaws, it can pave the way for a much wider range of risks. In a test by Vultus, a Brazilian cybersecurity company, an attack chain was identified that, in about seven hours, reached cloud environments, production infrastructure, and the personal and financial data of a large Brazilian organization.
The case was featured in the Ares Kill Chains Breakdownon Vultus' YouTube channel. The initiative uses real-life cases, with identities and sensitive information preserved, to explain how kill chains work in practice—that is, how seemingly independent steps can connect to generate a significant impact on the business.
In the analyzed scenario, the entry point was an authentication credential present in the public code of an application. This credential allowed access to a diagnostic endpoint that provided a snapshot of the application's memory. Based on the analysis of this data, the Ares by Vultus identified credentials and access contexts that enabled the mapping of new assets and permissions in a cloud environment.
Among the identified pathways were access to the AWS secrets manager, with over 700 credentials of varying scopes, and the ability to access file repositories containing sensitive personal information, biometric data, and financial records. The test also revealed administrative access to production resources in Kubernetes, as well as a route that allowed the enumeration of accounts, groups, and policies in the corporate Active Directory.
In one of the areas analyzed, there was potential to access data related to more than 60 million e-commerce orders, including information such as name, email, phone number, CPF (Brazilian tax identification number), address, and payment details. Vultus emphasizes that the work followed the limits defined within the scope of the test: the data was only enumerated, without exfiltration, and there was no alteration of systems, prices, applications, or production environments.
“The most relevant point in this case is not an isolated flaw, but the connection between them. An exposed credential can transform into legitimate access to other systems and, therefore, be more difficult to detect than a conventional intrusion attempt,” says Rodrigo Gava, CTO of Vultus. “When you only look at the number of vulnerabilities, there is a risk of losing sight of the most dangerous route: the one that connects an initial exposure to assets capable of affecting data, operations, and revenue.”
Beyond the production data and resources, the assessment identified a potential route to Active Directory. With an integration account available in the environment, it was possible to map over 70,000 user accounts, groups, and security policies. This step, which did not include attempts at privilege escalation or lateral movement beyond the authorized scope, demonstrated how a poorly segmented cloud infrastructure can create unwanted bridges between applications, services, and corporate environments.
In the preview of the 2027 Panorama, cyber risk indicators point to a scenario in which attacks not only become more likely, but also potentially more impactful. The I&E Index, which measures the probability of incidents occurring, reaches 9.06, compared to 7.57 in 2026, a 20% increase. The KillChain Score, which represents the potential impact of an attack, rises from 8.28 to 9.00, a 9% increase. For Vultus, the combination of these two trends indicates an environment where the attack surface continues to expand, while the damage capacity of incidents remains high.
For Gava, the case illustrates why the response to security assessments needs to be driven by the attack trajectory, not just the volume of technical findings. “AI-powered tools can test a digital surface with much greater speed and scope. This increases the number of vulnerabilities identified, but also gives companies the opportunity to prioritize what really needs to be stopped first: revoking and rotating credentials, closing the source of exposure, and reducing excessive permissions. Then comes the structural work of reviewing identities, access, and segmentation.”
Ares, autonomously, identified 14 critical vulnerabilities, two high-level vulnerabilities, five medium-level vulnerabilities, seven low-level vulnerabilities, and three informational vulnerabilities. For Vultus, the numbers help to quantify the challenge, but they do not replace an understanding of the chain of vulnerabilities between the assets and permissions found. The full content of the case will be detailed in series Ares Kill Chains Breakdown, with a technical and educational focus, preserving the identity of the organization involved and the ethical limits of an authorized assessment.



