Threat actors are actively exploiting intentionally vulnerable web applications used for security training and internal testing (including DVWA, OWASP Juice Shop, Hackazon, and bWAPP) when they are mistakenly exposed to the public Internet, using them as an entry point into enterprise cloud environments. Reporting based on a Pentera investigation described evidence of real-world abuse leading to follow-on activity such as cryptominer deployment, webshell placement, and pivoting deeper into sensitive systems—especially when these apps are deployed from privileged cloud accounts and paired with weak configurations.
Pentera reported finding 1,926 live exposed instances across AWS, GCP, and Azure, frequently associated with over-permissioned IAM roles and poor hygiene such as default credentials and failure to follow least-privilege practices. The exposed environments could enable access to cloud storage (e.g., S3, GCS, Azure Blob Storage), secrets stores (e.g., AWS Secrets Manager), container registries, and in some cases administrative control of cloud accounts; impacted organizations cited in coverage included major vendors such as Cloudflare, F5, and Palo Alto Networks, which were notified and reportedly remediated affected exposures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On publication of the research, Pentera warned that intentionally vulnerable training and demo applications left on the public internet can be used to breach enterprise cloud environments. The disclosure highlighted active exploitation, cloud credential theft via metadata services, and the risk posed to Fortune 500 firms and security vendors.
Pentera reported that exposed instances linked to major technology and security companies, including Cloudflare, F5, and Palo Alto Networks, were responsibly disclosed before publication. According to the research, the organizations remediated the exposed training applications after notification.
The investigation found evidence that attackers were already exploiting some exposed training apps in the wild, especially DVWA deployments. About 20% of 616 discovered DVWA instances contained malicious artifacts including XMRig cryptominers, persistence scripts such as watchdog.sh, and a PHP webshell named filemanager.php.
Among the validated cloud-hosted instances, Pentera found 165 with attached IAM roles and 109 with over-permissioned identities that could enable lateral movement or even full administrative access. The research showed that exposed training apps were not isolated test systems but often connected to real production cloud environments.
Pentera researcher Noam Yaffe found the Hackazon training app running on a real AWS EC2 production instance and exploited a file-upload flaw to achieve remote code execution. He then accessed the instance metadata service, stole temporary cloud credentials, and found an attached IAM role with AdministratorAccess, demonstrating a path from app exposure to full cloud compromise.
Using fingerprints for 10 intentionally vulnerable applications and internet-wide search tools such as Shodan and Censys, Pentera identified more than 10,000 candidate exposures and verified 1,926 live internet-accessible instances across 1,626 servers. The exposed apps included DVWA, OWASP Juice Shop, Hackazon, and bWAPP, many hosted in AWS, Google Cloud, and Azure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.