Feb 3, 2023 "I don't need no zero-dayz" - Docker Container Images (1/4) This post is the first part of a series on our recent adventures into DockerHub. You may be interested in the next instalments, which are: * Layer Cake: How Docker Handles 11 min read
Jan 31, 2023 We're Out Of Titles For VPN Vulns - It's Not Funny Anymore (Fortinet CVE-2022-42475) As part of our Continuous Automated Red Teaming and Attack Surface Management capabilities delivered through the watchTowr Platform, we analyse vulnerabilities in technology that are likely to be prevalent across 12 min read
Dec 7, 2022 Why It's Not Worth Goading Us On A Friday - CVE-2022-36537 At Scale At watchTowr, the security of our client's external systems is of priority. And as hackers, bugs are our passion. It's our job to understand emerging weaknesses, 18 min read
Nov 8, 2022 Text4Shell++ - Where There’s Smoke, There’s Fire (Or at least some ash) As part of our Attack Surface Management capabilities delivered through the watchTowr Platform, we analyse vulnerabilities in technology that is likely to be prevalent across 7 min read
Nov 2, 2022 OpenSSL 3.0.7 - Otherwise Known As, The Hype That Was Not Finally, it is midnight (in my timezone, at least) and the wait is over - OpenSSL have published details of their second ever critical severity, nope high-severity (**amended after disclosure) 5 min read
Oct 27, 2022 CVE-2022-44889 - Text4Shell Analysed As part of our Attack Surface Management capabilities delivered through the watchTowr Platform, we analyse vulnerabilities in technology that is likely to be prevalent across the attack surfaces of our 5 min read
Oct 9, 2022 All Around The World: The Common Crawl Dataset At watchTowr, we're big believers that data is power, and ultimately data drives security initiatives - like Attack Surface Management, which we then use to power continuous security testing 9 min read
Aug 4, 2022 Seasons In The Abyss - Diving into OpenVPN Access Server Here at watchTowr, we like to proactively audit security-critical codebases which we notice our clients rely on. This feeds our ability to keep external attack surfaces secure, as we 23 min read
Jul 1, 2022 1x Enterprise IAM vs 1x Slanty Boi OpenAM CVE-2022-34298 As part of our Attack Surface Management capabilities delivered through the watchTowr Platform, we perform zero-day vulnerability research in prevalent technology that we see across 8 min read