WordPress
Malware redirect from an outdated plugin
A membership organisation's site started sending visitors to a spam domain after an unpatched plugin was exploited. We removed the injected code, restored a clean version, locked down the stack, and moved them onto monitoring so the next attempt is caught early.
Legacy .NET
A breach through an unsupported framework
A logistics company's customer portal ran on an old .NET framework that no longer received security patches. Attackers used a known vulnerability to get in. We contained it, closed the hole, and mapped a staged upgrade onto a supported version so the platform was safe to run again.
Native app
A neglected app breaking on the latest OS
A member app had gone a couple of years without updates. After an OS release it started crashing on launch, and the app stores flagged it for outdated APIs. We updated the SDKs and dependencies, fixed the crashes, got it back through review, and put it on a maintenance cycle so it stays current.