Terry Bradley Terry Bradley

Our Penetration Testing Process: Thorough, Repeatable, and Human-Led

A penetration test should do more than produce a list of vulnerabilities. It should provide an accurate picture of your organization’s security while being conducted in a structured, repeatable, and minimally disruptive manner.

At Mile High Cyber, we’ve refined our testing process to balance technical depth with operational reliability. Every engagement follows a proven methodology, combining commercial security tools with extensive manual testing performed by experienced penetration testers. The result is a comprehensive assessment that identifies meaningful security risks without disrupting your business operations.

Read More
Terry Bradley Terry Bradley

Attackers Are Quietly Testing Stolen Passwords Against Your Microsoft Tenant

Attackers are quietly validating stolen passwords against Microsoft 365 tenants using spoofed OAuth client IDs — a technique that leaves no application name in your sign-in logs and never trips a "successful login" alert. Two campaigns have already hit nearly 4,000 tenants, and if your conditional access policies only cover known apps, you likely wouldn't see it happening.

Read More
Terry Bradley Terry Bradley

How to Pick a Good Pen Test Vendor

Choosing the right penetration testing company can make the difference between a generic vulnerability report and meaningful security improvements. Learn the key questions to ask, red flags to avoid, and how to evaluate penetration testing vendors based on expertise, methodology, reporting quality, and real-world value.

Read More
Terry Bradley Terry Bradley

AI Wrote Your Code. Who’s Testing Its Security?

AI coding assistants are helping development teams build software faster than ever. They can generate code, create tests, explain APIs, and accelerate everything from prototypes to production features.

But there’s one thing AI can’t guarantee:

That the application is secure.

Read More
Terry Bradley Terry Bradley

Ransomware Is Getting Faster with AI

A recent report from Sysdig describes JADEPUFFER, what researchers believe may be the first documented example of an AI agent autonomously carrying out a ransomware attack—from initial compromise all the way through database extortion.

The important takeaway isn't that AI has created a new kind of ransomware. It's that AI is beginning to automate the entire attack lifecycle.

According to the research, the AI agent exploited a known vulnerability, searched for credentials, moved laterally through the environment, adapted when it encountered errors, and ultimately encrypted and deleted database records—all with little apparent human intervention.

That should get every security leader's attention.

Read More
Terry Bradley Terry Bradley

AI Is Changing Penetration Testing — Your Security Partner Shouldn't Just Generate Reports

Artificial intelligence is transforming how organizations build software—and how attackers find ways to exploit it.

According to Cobalt's 2026 AI & Pentesting Pulse Report, AI and large language model (LLM) applications produce high-risk security findings at nearly three times the rate of conventional software. Even more concerning, two out of every three high-risk AI vulnerabilities remain unresolved after testing.

The problem isn't that organizations aren't testing. The problem is that too many penetration tests end the moment the report is delivered.

Read More
Terry Bradley Terry Bradley

How to Choose the Right vCISO for Your Organization

Hiring a full-time Chief Information Security Officer (CISO) isn’t realistic for many organizations. That’s why more businesses, schools, local governments, and nonprofits are turning to Virtual Chief Information Security Officer (vCISO) services.

A good vCISO provides executive cybersecurity leadership at a fraction of the cost of a full-time CISO—but choosing the right partner is critical.

Read More
Terry Bradley Terry Bradley

Why Web Application Testing Matters: Lessons from the Texas License System Breach

A recent data breach involving a Texas Parks and Wildlife Department license system vendor exposed personal information for more than 3 million people, including driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses.

This incident is a reminder that some of the most serious security risks are not found on the internal network. They are found in the applications organizations use to collect, process, and store sensitive information.

Read More
Terry Bradley Terry Bradley

Do I Need an Internal, External, or Web App Pen Test?

One of the most common questions we hear is, “What kind of pen test do we actually need?”

It’s a reasonable question. Most organizations know they need some kind of security testing, either because a customer asked for it, cyber insurance requires it, or they simply want to understand their risk. But the terminology can get confusing quickly. Internal, external, web application — they all sound similar, but they answer different security questions.

Read More
Terry Bradley Terry Bradley

How Much Does a Pen Test Cost in 2026?

“How much does a penetration test cost?” The honest answer is: it depends. That is not always a satisfying answer, especially if you are trying to build a budget, respond to an auditor, satisfy a customer security questionnaire, or meet a cyber insurance requirement.

Read More
Terry Bradley Terry Bradley

What Is SIM Swapping and Should I Be Concerned?

Most people think of their phone number as just a way to receive calls and texts. Attackers see it differently. To them, your phone number may be a way into your email, bank account, business systems, social media, or cryptocurrency accounts.

That is the basic idea behind SIM swapping.

Read More
Terry Bradley Terry Bradley

Understanding How Attackers Think and Helping You Avoid Threats with Terry Bradley from Mile High Cyber

The Cybersecurity Defenders Podcast is an accessible but technical cybersecurity show focused on “the people who keep the internet safe.” It blends recent cybersecurity news, interviews with practitioners and industry experts, analysis of adversary tactics, techniques, and procedures, and occasional hacker history. The show appears to be produced by LimaCharlie and publishes regularly, with recent episodes covering topics like AI security, security operations, threat intelligence, penetration testing, and long-term cybersecurity strategy. Overall, it is aimed at defenders who want practical, current, technically grounded insight without turning the show into pure vendor marketing or overly academic analysis

Read More
Terry Bradley Terry Bradley

Mythos Cybersecurity Announcement: Separating Facts from Hype

Anthropic’s recent Mythos announcement has sparked a wave of headlines about AI-powered hacking, autonomous cyberattacks, and the future of offensive security. Some of the coverage makes it sound like AI can now break into any company at will.

That is not the reality.

Read More
Terry Bradley Terry Bradley

Penetration Testing Vital Even Before the New HIPAA Rules Are Final

Healthcare organizations should not wait for the final HIPAA Security Rule updates to start validating their security posture. Although OCR has not yet finalized the proposed changes, the direction is already clear: healthcare entities and business associates are under growing pressure to implement more specific, defensible cybersecurity safeguards for electronic protected health information (ePHI). In March 2026, OCR Director Paula Stannard publicly defended the proposed updates while noting that OCR still had not decided which proposals would ultimately be finalized, and warned that “the cost of doing nothing is very high.”

Read More
Terry Bradley Terry Bradley

Vulnerability Scan vs. Pen Test: A CEO’s Buyer Guide

If you’re a CEO, you’ve probably had this moment: someone tells you “we need a pen test,” someone else says “we already run scans,” and now you’re stuck wondering whether you’re hearing two names for the same thing.

They’re not the same—and the difference matters, because they’re designed to answer two totally different questions.

A vulnerability scan is essentially a wide-angle lens. It’s automated, repeatable, and good at finding known issues across lots of systems: missing patches, exposed services, weak configurations, outdated software. It’s the kind of thing you want running on a cadence because your environment changes constantly. New machines appear, old ones get forgotten, updates fall behind, and security settings “drift.”

A penetration test is different.

Read More
Terry Bradley Terry Bradley

Mile High Cyber Joins SIPA, Expanding Streamlined Cybersecurity Access for Colorado Government Entities

Colorado Springs, CO — Mile High Cyber, a Colorado-based cybersecurity consulting firm, announced today that it has joined the Statewide Internet Portal Authority (SIPA) vendor program, making it easier for Colorado state and local government entities to procure cybersecurity services through pre-approved, streamlined contracting mechanisms.

Read More
Terry Bradley Terry Bradley

Faster and better

Attackers are using automation and AI to scout targets continuously, create incredibly convincing phishing campaigns, and gain initial access.

Read More
Terry Bradley Terry Bradley

8 Things Devs Did Wrong That Got Their Apps Hacked

Discover the eight most common developer mistakes that lead to app breaches—from hard-coded credentials and outdated libraries to IDOR vulnerabilities and skipped security testing. Learn how Mile High Cyber helps development teams secure apps before attackers exploit them.

Read More