<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b" -->

---
title: CISO thought he had a &#x27;r3@lg00dp@$$w0rd&#x27; but forgot to patch
description: A penetration tester recounts auditing a law firm that spent half a million dollars on security remediation yet still failed to patch Windows systems against...
canonical: https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CISO thought he had a &#x27;r3@lg00dp@$$w0rd&#x27; but forgot to patch | daily.dev
og:description: A penetration tester recounts auditing a law firm that spent half a million dollars on security remediation yet still failed to patch Windows systems against...
og:url: https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b
og:image: https://api.daily.dev/og/posts/DuAgfLk1b.png
og:image:alt: CISO thought he had a &#x27;r3@lg00dp@$$w0rd&#x27; but forgot to patch
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

**[The Register](https://daily.dev/sources/theregister)** · 4 min read · 0 upvotes · 0 comments

## Summary

A penetration tester recounts auditing a law firm that spent half a million dollars on security remediation yet still failed to patch Windows systems against BlueKeep, a wormable RCE vulnerability from 2019. Using BlueKeep, the tester accessed 2,500 computers and found plaintext passwords, including the CISO's own password, a laughably weak 'r3@lg00dp@$$w0rd' (realgoodpassword with symbol substitutions). The CISO outed himself by objecting when the password appeared on screen during a vulnerability presentation to firm executives.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/security/2026/10/01/ciso-thought-he-had-a-r3lg00dpw0rd-but-forgot-to-patch/5300314>

## Questions this post answers

### what is the BlueKeep vulnerability and why is it still dangerous if unpatched

BlueKeep is a remote code execution flaw in Windows' Remote Desktop Protocol, exploitable via port 3389, affecting Windows 2000, Windows Server 2008 R2, and Windows 7, with related DejaBlue vulnerabilities affecting Windows 10. It is wormable, meaning it can spread automatically between systems, and remains a serious risk years after its 2019 discovery if machines are not patched.

_daily.dev helps security teams keep tabs on unpatched RCE flaws like BlueKeep before they're exploited._

### does substituting symbols and numbers for letters actually make a password secure

No, substituting characters like '@' for 'a' or '0' for 'o' does not meaningfully strengthen a password. A security consultant cracked a law firm CISO's password 'r3@lg00dp@$$w0rd' (a leetspeak version of 'realgoodpassword') during a penetration test, showing this common technique offers little real protection, especially when passwords are also stored in plain text.

_developers weighing password policies can track practical security lessons like this on daily.dev._

## Similar posts on daily.dev

- [CISA: Windows BlueHammer flaw now exploited by ransomware gangs](https://daily.dev/posts/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs-8msc5m9tl) · BleepingComputer · 1 upvotes · 0 comments
- [BlueHammer Microsoft Defender Flaw Exploited in Ransomware Attacks](https://daily.dev/posts/bluehammer-microsoft-defender-flaw-exploited-in-ransomware-attacks-epvsqsotd) · Security Boulevard · 0 upvotes · 0 comments
- [CISA orders feds to patch Windows flaw exploited as zero-day](https://daily.dev/posts/cisa-orders-feds-to-patch-windows-flaw-exploited-as-zero-day-gw4v2yydq) · BleepingComputer · 1 upvotes · 0 comments
- [Windows shell spoofing vulnerability puts sensitive data at risk](https://daily.dev/posts/windows-shell-spoofing-vulnerability-puts-sensitive-data-at-risk-39k3nizjs) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#windows](https://daily.dev/tags/windows)

[View this post on daily.dev](https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch","url":"https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b"},"datePublished":"2026-10-01T13:36:52.176Z","dateModified":"2026-10-01T13:37:14.988Z","description":"A penetration tester recounts auditing a law firm that spent half a million dollars on security remediation yet still failed to patch Windows systems against...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ddf9aa022eadcbc883a5fea4b1de0b28?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ddf9aa022eadcbc883a5fea4b1de0b28?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,windows","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-duagflk1b#faq","mainEntity":[{"@type":"Question","name":"what is the BlueKeep vulnerability and why is it still dangerous if unpatched","acceptedAnswer":{"@type":"Answer","text":"BlueKeep is a remote code execution flaw in Windows' Remote Desktop Protocol, exploitable via port 3389, affecting Windows 2000, Windows Server 2008 R2, and Windows 7, with related DejaBlue vulnerabilities affecting Windows 10. It is wormable, meaning it can spread automatically between systems, and remains a serious risk years after its 2019 discovery if machines are not patched. daily.dev helps security teams keep tabs on unpatched RCE flaws like BlueKeep before they're exploited."}},{"@type":"Question","name":"does substituting symbols and numbers for letters actually make a password secure","acceptedAnswer":{"@type":"Answer","text":"No, substituting characters like '@' for 'a' or '0' for 'o' does not meaningfully strengthen a password. A security consultant cracked a law firm CISO's password 'r3@lg00dp@$$w0rd' (a leetspeak version of 'realgoodpassword') during a penetration test, showing this common technique offers little real protection, especially when passwords are also stored in plain text. developers weighing password policies can track practical security lessons like this on daily.dev."}}]}
```

