CISO Thought He Had a 'r3@lg00dp@$$w0rd' but Forgot to Patch
The Register, Thursday, October 1st, 2026
A pen tester found a law firm CISO left BlueKeep unpatched and used a weak leetspeak password.
In The Register's PWNED column, Cobalt's Joe Brinkley, 'The Blind Hacker,' recounts pen-testing a business being acquired by a national law firm that had spent roughly half a million dollars remediating issues Brinkley found a year earlier.
The firm still failed to patch Windows machines against the BlueKeep remote code execution flaw, and Brinkley found that the CISO relied on a password that merely swapped letters for symbols.
The story is a reminder that tooling spend means little without patching and genuinely strong passwords.