According to The Register, a penetration test commissioned by a large national law firm turned up an embarrassing security lapse. Joe Brinkley, director of offensive security research at Cobalt, was testing a smaller business the firm planned to acquire when he found that the firm had failed to patch BlueKeep, a wormable remote code execution vulnerability in Windows Remote Desktop Protocol that was disclosed and patched in 2019. Exploiting the flaw gave Brinkley access to 2,500 of the organization's computers.

Inside, Brinkley found passwords stored in plaintext and usernames designed for 'security by obscurity,' such as 'Yellow Banana' and 'Red Apple.' The password for the Yellow Banana account was 'r3@lg00dp@$$w0rd' — a leetspeak version of 'realgoodpassword.' During a presentation to executives, Brinkley showed a screenshot of the password, prompting the CISO to blurt out an expletive and ask why his password was on screen, inadvertently revealing that he was Yellow Banana.

The firm had previously been audited by Brinkley and had spent roughly half a million dollars on security software from vendors such as Reliaquest and Dell to address his findings. That investment did not include patching BlueKeep, which remains a risk on unpatched Windows systems. The Register notes that the incident underscores the importance of applying patches promptly, avoiding predictable passwords, enabling two-factor authentication, and encrypting stored passwords.