"Why the f*** is my password on the screen?" the CISO asked — aloud, in front of the room — and in doing so revealed both his identity and the scale of a breakdown that began with unpatched Windows servers and ended with the chief information security officer using "r3@lg00dp@$$w0rd" as a password.
Joe Brinkley’s penetration test and the law firm’s prior remediation
Security consultant Joe Brinkley, known as "The Blind Hacker," was brought in by a large, national law firm to penetration-test a smaller business the firm planned to acquire. Brinkley had audited the same law firm a year earlier and reported a number of security holes; at that time the attorneys invested in remediation and bought security products from Reliaquest and Dell. "I shredded them. They were not in a very good security posture," Brinkley told the reporter, and the firm "spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition."
BlueKeep, DejaBlue, and a failure to patch
Brinkley’s follow-up assessment found that Windows systems had not been patched against BlueKeep — a major remote code execution vulnerability discovered, patched, and exploited in 2019. The source describes BlueKeep as affecting Windows 2000, Windows Server 2008 R2, and Windows 7; related vulnerabilities called DejaBlue affected Windows 10. The underlying flaw resides in Windows’ Remote Desktop Protocol and allows attackers to execute remote code via port 3389. BlueKeep and related problems are "wormable," meaning a successful exploit can spread from one system to another. In this case the known, patched vulnerability remained a live avenue into the firm’s network.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePlain-text passwords, whimsical usernames, and the reveal
Once inside via the BlueKeep flaw, Brinkley found that passwords were stored in plain text and "easy to dump into a file, no decryption necessary." Usernames on the system had been replaced with nonstandard labels — examples given were "Yellow Banana" and "Red Apple" — apparently intended as security by obscurity. Brinkley discovered the account labelled "Yellow Banana" and captured its password: "r3@lg00dp@$$w0rd," described by the source as the string "realgoodpassword" with symbol and number substitutions.
Brinkley included a screenshot of the captured credential in a presentation to the law firm’s executives. While explaining that he had managed to penetrate 2,500 of the organization’s computers, the CISO reacted to the slide and unintentionally admitted ownership of the account by exclaiming the quoted line. The sequence made plain two failures at once: an unpatched remote-access vulnerability and weak credentials held by the person responsible for security.
Reliaquest, Dell and a half-million-dollar remediation that missed the basics
The firm had purchased security software from Reliaquest and Dell and spent, Brinkley estimated, "probably a half a million dollars" on remediation tied to the merger. Yet the investment did not translate into complete mitigation of well-known Windows vulnerabilities or into modern password hygiene for privileged accounts. The episode illustrates a gap between procurement of security products and execution of basic operational controls such as timely patching and credential protection.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The incident underscores the criticality of prioritizing patch management for remote-access services (Remote Desktop Protocol on port 3389 was the vector here) and of removing or isolating legacy Windows builds that remain vulnerable to BlueKeep and related flaws.
- Procurement leaders and executives: Purchasing detection and remediation tools — even at scale — does not replace process. The firm’s half-million-dollar spend did not prevent compromise because it didn’t resolve basic operational steps like applying available patches and encrypting stored credentials.
- End users and the general public: Credential hygiene matters at every level. The CISO’s loud reaction became the evidence of a weak, guessable password held by the organization’s security lead; the account name and the password were both easily exposed once an exploit succeeded.
The takeaways are narrow and stark: known remote-code vulnerabilities patched in 2019 remained exploitable in this environment; once an exploit delivered access, credentials were immediately harvested because they were stored and presented in plain text; and an attempted layer of obscurity — unusual account names — did nothing to prevent discovery or to protect privileged accounts. Brinkley’s final, practical recommendations in the source were simple: always patch Windows systems as soon as patches are available, avoid "cutesy" passwords, enable two-factor authentication, and encrypt stored passwords.
Those are small, specific fixes with immediate impact. The harder question left by the episode is organizational: when a merger or procurement cycle mobilizes large security budgets, who ensures that the everyday operational work — patching, credential management, and multi-factor protection — actually gets done?




