May 17, 2024 QNAP QTS - QNAPping At The Wheel (CVE-2024-27130 and friends) Infosec is, at it’s heart, all about that data. Obtaining access to it (or disrupting access to it) is in every ransomware gang and APT group’s top-10 19 min read
Apr 16, 2024 Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400) Welcome to April 2024, again. We’re back, again. Over the weekend, we were all greeted by now-familiar news—a nation-state was exploiting a “sophisticated” vulnerability for full 12 min read
Feb 9, 2024 Ivanti Connect Secure CVE-2024-22024 - Are We Now Part Of Ivanti? As astute readers of our Twitter account (https://twitter.com/watchtowrcyber) and blog will know, we’ve recently been heavily involved in understanding the recent spatter of vulnerabilities in Ivanti 9 min read
Jan 18, 2024 The Second Wednesday Of The First Month Of Every Quarter: Juniper 0day Revisited Who likes vulnerabilities in appliances from security vendors? Everyone loves appliance vulnerabilities! If, by 'everyone', you mean various ransomware and APT groups of course (and us). Regular watchTowr- 9 min read
Jan 13, 2024 Welcome To 2024, The SSLVPN Chaos Continues - Ivanti CVE-2023-46805 & CVE-2024-21887 Did you have a good break? Have you had a chance to breathe? Wake up. It’s 2024, and the chaos continues - thanks to Volexity (Volexity’s writeup), the industry 6 min read
Oct 20, 2023 Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall Here at watchTowr, we just love attacking high-privilege devices (and spending hours thinking of awful titles [see above]). A good example of these is the device class of ‘next 19 min read
Oct 11, 2023 The Sky Has Not Yet Fallen - Curl (CVE-2023-38545) There are few packages as ubiquitous as the venerable cURL project. With over 25 years of development, and boasting “over ten billion installations”, it’s easy to see why a 7 min read
Oct 2, 2023 90s Vulns In 90s Software (Exim) - Is the Sky Falling? A few days ago, ZDI went public with no less than six 0days in the popular mail server Exim. Ranging from ‘potentially world-ending' through to ‘a bit of 6 min read
Aug 25, 2023 CVE-2023-36844 And Friends: RCE In Juniper Devices As part of our Continuous Automated Red Teaming and Attack Surface Management technology - the watchTowr Platform - we're incredibly proud of our ability to discover nested, exploitable vulnerabilities across 17 min read
Jun 13, 2023 Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was When Lexfo Security teased a critical pre-authentication RCE bug in FortiGate devices on Saturday 10th, many people speculated on the practical impact of the bug. Would this be a 10 min read
Jun 9, 2023 Fortinet and The Accidental Bug As part of our Continuous Automated Red Teaming and Attack Surface Management capabilities delivered through the watchTowr Platform, we see a lot of different bugs in a lot of different 9 min read
Apr 10, 2023 Adobe Commerce (Magento) CVE-2022-24086 : Return Of The Text Interpolation In our latest blog post, we'll be discussing a vulnerability that - while not new - is shrouded in mystery. Ranging from bizarre and false PoCs circulating on Twitter, to 7 min read
Feb 23, 2023 What Does This Key Open? - Docker Container Images (4/4) This post is the fourth part of a series on our recent adventures into DockerHub. Before you read it, you may be interested in the previous instalments, which are: * " 14 min read
Feb 15, 2023 Learning To Crawl (For DockerHub Enthusiasts, Not Toddlers) - Docker Container Images (3/4) This post is the third part of a series on our recent adventures into DockerHub. Before you read it, you are advised to look at the part other parts of 10 min read
Feb 9, 2023 Layer Cake: How Docker Handles Filesystem Access - Docker Container Images (2/4) This post is the second part of a series on our recent adventures in DockerHub. Before you read it, you may want to check out the other posts of this 14 min read