InfoGuard Labs (Switzerland)
infoguard-labs · B · active
Swiss security research lab; discovered via the 'Ghost-Sender' Exchange Online spoofing disclosure surfaced in NCSC-CH post 12619 (2026-06-10). Strong CH/EU public-sector relevance. Candidate; promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://labs.infoguard.ch/ (listing has titles+dates), then fetch the article at https://labs.infoguard.ch/posts/<slug>/; bridge 'url' works; the WebFetch summariser strips the 'labs.' subdomain (infoguard.ch/posts/<slug>/ 404s), so keep the labs. host for the drill.. AVOID: No feed and the listing post-cards are JS-rendered (raw HTML exposes only category/tag archive links). Don't drop the 'labs.' subdomain on article URLs, bare infoguard.ch/posts/<slug>/ 404s.. | 2026-07-05 admiralty audit: B, original Swiss vuln/malware research, strong CH/EU relevance; stays active. Keep the 'labs.' subdomain on drill URLs (bare infoguard.ch/posts/<slug>/ 404s). | 2026-08-05: RECIPE GAP, https://labs.infoguard.ch/ returns HTTP 200 but the post cards are JS-rendered and the raw body exposed no article links at all; no dated items could be enumerated by any transport tried. Needs a feed or sitemap probe before it can contribute. Not a demotion candidate (200, not a block). | 2026-08-09 RECIPE FIX: the standing 'JS-rendered listing, no extractable dates' gap is resolved; a working dated Atom/RSS feed exists at https://labs.infoguard.ch/rss.xml, returning full items with pubDate and article links. fetch_method switched webfetch -> rss. Consequence worth recording: the recipe gap had hidden this source's output from every prior run, and the first fetch through the fixed recipe surfaced a 22-CVE Swiss original-research disclosure (TeamDavid) that the pipeline had never covered.
Cited in 3 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 3).
- 22 CVEs in Tobit TeamDavid, a DACH-region self-hosted Microsoft 365 alternative: an unauthenticated heap leak hands over stored mailbox passwords, and the vendor stopped responding2026-08-09
- "Ghost-Sender": Exchange Online accepts spoofed inbound mail bypassing SPF/DKIM/DMARC when a third-party MX fronts the tenant, no vendor patch2026-06-10
- CVE-2026-44128 et al. SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five additional CVEs2026-05-09