watchTowr Labs
watchtowr · B · active
Edge-device exploit research, often ahead of vendor disclosures. RSS at https://labs.watchtowr.com/rss/. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://labs.watchtowr.com/rss/ 5 (RSS carries near-full body) then webfetch the /<slug>/ for full article. AVOID: Cadence is bursty (multiple posts in days then quiet) — sparse periods are normal, not a failure. WebFetch on the article 403'd once in this audit; RSS is the more reliable entry and already carries substantive body HTML.. | 2026-07-05 admiralty audit: B — original edge-device exploit research, often ahead of vendors; RSS carries substantive body, bursty cadence is normal. No status change.
Cited in 11 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 8).
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory — the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent2026-07-31
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed2026-07-13
- Edge and VPN appliances took three pre-auth RCE/overread disclosures in one week — Citrix NetScaler, WatchGuard Firebox, Kemp LoadMaster2026-07-05
- CVE-2026-8451 — Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC2026-07-01
- CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API2026-06-30
- Splunk Enterprise CVE-2026-20253: pre-auth RCE in the SIEM via an unauthenticated PostgreSQL sidecar proxy2026-06-14
- CVE-2026-20253 — Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy2026-06-14
- CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth command injection to root, now confirmed exploited and gateways backdoored2026-06-14
- CVE-2026-47344 et al. — TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today2026-06-10
- cPanel / WHM — two emergency TSRs inside ten days: post-CVE-2026-41940 fleet now facing CVE-2026-29201/29202/292032026-05-04