Sep 25, 2025 It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 We’re back, just over 24 hours later, to share our evolving understanding of CVE-2025-10035. Thanks to everyone who reached out after Part 1, and especially to the 3 min read
Feb 4, 2025 8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateur Surprise surprise, we've done it again. We've demonstrated an ability to compromise significantly sensitive networks, including governments, militaries, space agencies, cyber security companies, supply chains, software 41 min read
Jan 8, 2025 Backdooring Your Backdoors - Another $20 Domain, More Governments After the excitement of our .MOBI research, we were left twiddling our thumbs. As you may recall, in 2024, we demonstrated the impact of an unregistered domain when we subverted 16 min read
Sep 11, 2024 We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI Welcome back to another watchTowr Labs blog. Brace yourselves, this is one of our most astounding discoveries. Summary What started out as a bit of fun between colleagues while avoiding 21 min read
Mar 19, 2023 ProjeQtOr - <10.2.2 Direct Object Injection Vulnerability As part of our Continuous Automated Red Teaming and Attack Surface Management technology within the watchTowr Platform, we perform zero-day vulnerability research in technology that we see across the 3 min read
Aug 23, 2022 The Perils of Expired Domains: We're Reading Your Email When we think about attack surfaces, historical thinking has thrown us at network services, web applications, APIs and other 'fuller stack' technology layers to review for high-impact 4 min read