Identifying a pre-auth RCE in a deployed core-banking module before regulators did.
Continuous PTaaS engagement uncovered a serialization flaw in a vendor module integrated into the bank's payment-gateway perimeter. Verified exploitation produced unauthenticated remote code execution against an internet-exposed service. Disclosed to the vendor, patched within 11 days, and retested before any external party detected the issue.