
RCE Vulnerability shambles Google Chrome Dev Channel
It has been reported that a recently patched severe remote code execution vulnerability flaw in the V8 JavaScript and WebAssembly engine used in Google Chrome and Chromium-based…
Security Assessments
Cyber Labs delivers vulnerability assessment and penetration testing (VAPT) services for organizations in Sri Lanka and Australia across web applications, mobile applications, APIs, networks, cloud environments, and business-critical infrastructure. Our consultants combine automated discovery with expert manual testing to identify weaknesses, prove real-world risk safely, and guide your team through remediation and retesting.

What it is
VAPT combines two complementary disciplines. Vulnerability assessment systematically discovers and prioritizes weaknesses across the agreed scope, while penetration testing safely attempts to exploit relevant findings and attack paths. The result is a business-focused view of what is exposed, what an attacker could achieve, and what your team should fix first.
Why it matters
A scanner report alone cannot explain whether a weakness is exploitable or how several lower-severity issues could be chained into a serious breach. A properly scoped VAPT engagement validates controls before an attacker does, reduces the attack surface, supports audit and compliance evidence, and gives technical teams clear remediation priorities.
Business outcomes
Assess web, mobile, API, network, cloud, and infrastructure targets under one coordinated VAPT programme.
Separate theoretical scanner findings from weaknesses that can create meaningful technical or business impact.
Give engineering and infrastructure teams evidence, risk context, and practical guidance for fixing the most important issues first.
Communicate exposure clearly to decision-makers while preserving the evidence and reproduction detail technical teams need.
Support security and audit requirements using a documented scope, repeatable methodology, findings, and remediation status.
Retest agreed findings to verify that fixes work and that the original attack path is no longer available.
Our approach
Each VAPT engagement is scoped around your assets, business context, and acceptable testing constraints. Automated tooling improves coverage, while manual analysis and controlled exploitation establish whether findings represent genuine risk.
Define objectives, in-scope assets, testing windows, user roles, exclusions, and escalation contacts before testing begins.
Map the attack surface and gather the technical context required to test the environment safely and efficiently.
Use appropriate automated tools to discover known weaknesses, exposed services, configuration issues, and potential attack paths.
Manually test authentication, authorization, business logic, input handling, configurations, and other controls relevant to the target.
Safely validate exploitable findings and likely attack chains within the agreed rules of engagement, without unnecessary operational impact.
Deliver an executive summary and detailed technical report with evidence, risk ratings, affected assets, and remediation recommendations.
Review findings with your stakeholders, support remediation decisions, and retest agreed fixes to confirm closure.
VAPT questions
Practical answers about scope, testing safety, reporting, and remediation.
The exact scope is agreed before testing. It can include web applications, mobile applications, APIs, external or internal networks, cloud services, servers, and other infrastructure. The engagement normally includes discovery, automated and manual testing, risk validation, reporting, remediation guidance, and agreed retesting.
A vulnerability assessment identifies and prioritizes potential weaknesses across the scope. Penetration testing goes further by manually investigating relevant findings and safely validating whether weaknesses or combined attack paths can be exploited.
Timing depends on the number and complexity of targets, testing depth, access level, and operating constraints. Cyber Labs confirms the schedule after scoping so coverage and expectations are clear before the engagement begins.
Testing is governed by an agreed scope and rules of engagement designed to control operational risk. Potentially disruptive techniques are excluded or separately approved, and escalation contacts and testing windows are defined in advance.
You receive an executive view of business risk and a technical report containing affected assets, evidence, severity, impact, and remediation guidance. Where included in scope, Cyber Labs also retests agreed findings and records their closure status.
Yes. A documented VAPT engagement can provide evidence for applicable security, governance, customer, and audit requirements. The exact testing scope and reporting should be aligned with the framework or contractual obligation you need to satisfy.
Related services
Relevant insights

It has been reported that a recently patched severe remote code execution vulnerability flaw in the V8 JavaScript and WebAssembly engine used in Google Chrome and Chromium-based…

In the ever-evolving landscape of cybersecurity, vulnerability management has transformed dramatically. What started as a reactive approach to patching known flaws has matured…

Cybersecurity & Infrastructure Security Agency (CISA) and the United States Coast Guard Cyber Command (CGCYBER) released a joint Cybersecurity Advisory (CSA) on june 23rd 2022…
Next step
We will walk through scope, timing and what the engagement would actually involve — no obligation.