watchTowr Labs
watchtowr · B · active
Edge-device exploit research, often ahead of vendor disclosures. RSS at https://labs.watchtowr.com/rss/. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://labs.watchtowr.com/rss/ 5 (RSS carries near-full body) then webfetch the /<slug>/ for full article. AVOID: Cadence is bursty (multiple posts in days then quiet); sparse periods are normal, not a failure. WebFetch on the article 403'd once in this audit; RSS is the more reliable entry and already carries substantive body HTML.. | 2026-07-05 admiralty audit: B, original edge-device exploit research, often ahead of vendors; RSS carries substantive body, bursty cadence is normal. No status change.
Cited in 8 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 6).
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent2026-07-31
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat', day three, no patch or root cause disclosed2026-07-13
- CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC2026-07-01
- CVE-2026-8037, Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API2026-06-30
- Splunk Enterprise CVE-2026-20253: pre-auth RCE in the SIEM via an unauthenticated PostgreSQL sidecar proxy2026-06-14
- CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy2026-06-14
- CVE-2026-47344 et al. TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today2026-06-10