// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 3 EXPLOIT IN THE LAST 24H→
A penetration tester compromised 2,500 computers at a U.S. law firm by exploiting BlueKeep, CVE-2019-0708. The CISO inadvertently incriminated himself during the results presentation.

Joe Brinkley, director of offensive security research at Cobalt, recently recounted how a penetration test conducted several years ago against a national U.S. law firm exposed a systemic cybersecurity failure. The organization had invested roughly half a million dollars in security tools after a prior audit, yet had not applied the patch for BlueKeep, a wormable vulnerability discovered in 2019. Brinkley gained access to approximately 2,500 computers and recovered passwords stored in plaintext, including the CISO's.

Key Takeaways
  • Joe Brinkley conducted the penetration test for a U.S. law firm: he exploited CVE-2019-0708 (BlueKeep) to compromise roughly 2,500 computers despite a roughly $500,000 security investment.
  • Passwords were stored in plaintext, requiring no decryption; the CISO used the username "Yellow Banana" and the password "r3@lg00dp@$$w0rd".
  • During the results presentation to executives, the CISO exclaimed, "Why the f*** is my password on the screen?", inadvertently incriminating himself.
  • The case illustrates the gap between security tool spending and fundamental operational practices like patching, with a trivial leetspeak password symbolizing the problem.
"Why the f*** is my password on the screen?" — Law firm CISO, during the penetration test presentation

The Failure Chain: From BlueKeep to Plaintext Credentials

The vulnerability CVE-2019-0708, known as BlueKeep, is a remote code execution (RCE) flaw in the Windows Remote Desktop Protocol service. According to the National Vulnerability Database, the CVSS score is 9.8 out of 10, rated CRITICAL, with a network attack vector, low complexity, and no privileges required. BlueKeep is wormable: it can propagate automatically between vulnerable systems without user interaction, a characteristic that makes it particularly dangerous in enterprise environments with many exposed endpoints.

The law firm had already been audited by Brinkley the previous year. "I shredded them. They were not in a very good security posture," the researcher recalled, referring to the findings of that first assessment. The organization then invested roughly $500,000 in security software, including ReliaQuest and Dell products, to strengthen its posture ahead of a merger or acquisition. "They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition," Brinkley stated.

Despite the investment, the Windows systems had not been patched against BlueKeep. Brinkley exploited the vulnerability to gain access to roughly 2,500 of the organization's computers. Once inside, he discovered that passwords were stored in plaintext: "passwords were stored in plain text and easy to dump into a file, no decryption necessary," according to the researcher's account. Among the recovered credentials were the username "Yellow Banana" and the password "r3@lg00dp@$$w0rd".

The Leetspeak Password and the Public Self-Incrimination

The password "r3@lg00dp@$$w0rd" is a leetspeak variant of the phrase "realgoodpassword," according to daily.dev. The substitution of letters with visually similar numbers and symbols — 'e' with '3', 'a' with '@', 'o' with '0', 's' with '$' — does not significantly increase entropy against modern automated attacks. Cracking engines like Hashcat and custom password lists treat leetspeak as a standard pattern, rapidly downgrading these variants to a level of computational simplicity.

The defining moment occurred during the presentation of the penetration test results to the law firm's executives. When Brinkley projected the recovered credentials, the CISO in the room exclaimed: "Why the f*** is my password on the screen?" The outburst involuntarily revealed that the organization's top security officer was the user "Yellow Banana," with a password that epitomized the very practice the role should have prevented.

The dossier does not specify whether the CISO remained in the role after the incident, nor whether the law firm ultimately completed the planned merger or acquisition. The organization's name has not been disclosed, nor the CISO's real identity beyond the compromised username.

Why Leetspeak Is No Longer Enough

The case highlights a persistent problem in the perception of credential security. Leetspeak was considered an effective obfuscation technique in the early 2000s, when password dictionaries were less sophisticated and transformation rules were not standardized in cracking tools. Today, Hashcat's expansion rules include dozens of preconfigured leetspeak variants, and dictionaries like RockYou2021 contain billions of real-world passwords that capture these patterns.

The critical issue is not the single password, but the combination of factors: a critical vulnerability known for years, a massive tool investment that failed to cover operational patching, plaintext credential storage, and a security culture that allowed the person in charge to consider a leetspeak variant of a common phrase acceptable. The CISO's password became the symbol of a system where security was perceived as a technology purchase, not an operational discipline.

What to Do Now

  • Verify the patching status of CVE-2019-0708 on all Windows systems with RDP enabled, prioritizing internet-exposed servers.
  • Review credential storage policies: no password should reside in plaintext on production systems or accessible repositories.
  • Implement multi-factor authentication for RDP access and limit service exposure via VPN or access gateway.
  • Evaluate patch management programs against operational metrics (mean time to remediate KEV vulnerabilities) rather than tool spend alone.

The Real Cost of "Security Theater"

The law firm's saga exposes a recurring paradox in cybersecurity: the equation of spending with protection is fallacious. Half a million dollars in software did not prevent a 2019 patch from remaining unapplied, nor did it prevent the security chief's credentials from being recoverable in plaintext. The CISO's reaction during the presentation — surprise more than awareness — suggests a culture where security was outsourced to vendors, not internalized as operational responsibility.

The case is not isolated in time: wormable vulnerabilities continue to be exploited years after patches are released, and unpatched endpoints remain a primary compromise vector. The difference here is the clarity of the symbol. When the security chief recognizes their own password on the screen, the gap between perception and reality becomes visible to the entire executive suite. This is not a technical failure: it is a governance failure.

For CISOs and boards reading this story, the question is not whether their systems are patched, but whether the answer to that question is independently verifiable beyond vendor reports. Verification, not procurement, is the dividing line between security theater and operational security.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. github.com
  2. daily.dev
  3. nvd.nist.gov
  4. cisa.gov
  5. support.citrix.com