Intentionally vulnerable training applications are widely used for security training, internal testing, and product demonstrations. Tools like OWASP Juice Shop, DVWA, Hackazon , and bWAPP are designed to be insecure by default, making them useful for learning how common attack techniques work in controlled cloud environments.
See also: North Korean hackers UNC1069 target crypto companies

The problem is not the applications themselves, but how they are often deployed and maintained in real cloud environments.
Pentera Labs examined how educational and demo applications are used in cloud infrastructures and identified a recurring pattern: applications intended for isolated use in labs were often found exposed to the public internet, running within active cloud accounts and associated with cloud identities with broader access than required.
Pentera Labs’ research found that these applications were often deployed with default settings, minimal isolation, and overly permissive cloud roles. The research revealed that many of these exposed educational environments were directly tied to active cloud identities and privileged roles, allowing attackers to extend well beyond the vulnerable applications themselves and potentially into the customer’s broader cloud infrastructure.
In these cases, a single exposed educational application can act as an initial point of entry. Once attackers are able to leverage the associated cloud identities and privileged roles, they are no longer limited to the original application or host. Instead, they may gain the ability to interact with other resources within the same cloud environment, significantly increasing the scope and potential impact of the breach.
As part of the research, Pentera Labs verified nearly 2,000 live, exposed educational applications, with nearly 60% hosted on customer-managed infrastructure running on AWS, Azure , or GCP.
The exposed educational environments identified during the research were not simply poorly configured. Pentera Labs saw clear evidence that attackers were actively exploiting this exposure in practice.
See also: Misconfigured Demo Environments: Cloud Backdoors for Enterprises

In the broader dataset of exposed educational applications, approximately 20% of cases were found to contain artifacts developed by malicious actors, including crypto-mining activity, webshells, and persistence mechanisms. These artifacts indicated a previous breach and ongoing abuse of the exposed systems.
The presence of active crypto-mining and preservation tools indicates that exposed educational applications are not only detectable but are already being exploited on a large scale.
The exposed and exploited environments identified during the research were not limited to small or isolated test systems. Pentera Labs observed this pattern of deployment in cloud environments affiliated with Fortune 500 organizations and leading cybersecurity vendors, including Palo Alto, F5 , and Cloudflare.
While individual environments varied, the underlying pattern remained consistent: an educational or demo application was deployed without adequate isolation, remained publicly accessible, and connected to privileged cloud identities.
Training and demo environments are often treated as low-risk or temporary assets. As a result, they are often exempt from standard security monitoring, access review, and lifecycle management processes. Over time, these environments can remain exposed long after their initial use.
The research shows that exploitation does not require zero-day vulnerabilities or advanced attack techniques. Default credentials, known vulnerabilities, and public exposure were enough to turn educational applications into entry points for broader cloud access.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: When training tools become a gateway to cloud attacks

Labeling an environment as “training” or “testing” does not reduce its risk. When exposed to the internet and connected to privileged cloud identities, these systems become part of an organization’s effective attack surface.
