Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

watchTowr

@watchTowr@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

477 Followers
0 Following
49 Posts
Joined December 05, 2024
Website:
https://watchtowr.com
Open post
watchTowr @watchTowr@infosec.exchange
· 1w ago
RE: https://infosec.exchange/@watchTowr/117338396418850285 We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are expected early next week. Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics. As always, watchTowr Platform customers have access to this information and already have the information needed to reduce exposure.
Open quoted post
Quoting
watchTowr
@watchTowr@infosec.exchange
We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the limited information available is credible, and we are thus imploring organizations to take it seriously. Active watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
Open quoted post
infosec.exchange

watchTowr: "We are currently rapidly reacting to rumors that …" - Infosec Exchange

6
1
5
1
Open post
watchTowr @watchTowr@infosec.exchange
· 1w ago
RE: https://infosec.exchange/@watchTowr/117338396418850285 Update: We have high confidence in the information and have verified it with authoritative sources. Please, react NOW.
Open quoted post
Quoting
watchTowr
@watchTowr@infosec.exchange
We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the limited information available is credible, and we are thus imploring organizations to take it seriously. Active watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
Open quoted post
infosec.exchange

watchTowr: "We are currently rapidly reacting to rumors that …" - Infosec Exchange

2
1
2
0
Open post
watchTowr @watchTowr@infosec.exchange
· 7mo ago

2026, the year of the AI-driven attacker that could do back flips, they said.

Meanwhile, there's a magic number that allows Auth Bypass against Ivanti EPM (CVE-2026-1603)

something about a pledge 🙄

63
10
44
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

~150 S3 abandoned buckets. 8M+ requests. Two months. Software updates, binaries, VMs and more.

This week, AWS rolled out namespaces for new S3 buckets - finally.

This is why offensive security research is so important - to move the needle.

https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/

labs.watchtowr.com
38
6
24
0
Open post
watchTowr @watchTowr@infosec.exchange
· 5mo ago

whoever bought http://a-fun-hostname-for-f5-to-mark-as-an-ioc.com and redirected it to our blog post - please reach out, we love you

a-fun-hostname-for-f5-to-mark-as-an-ioc.com
28
0
12
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

speak soon

29
3
5
0
Open post
watchTowr @watchTowr@infosec.exchange
· 5mo ago

The Internet is falling down, falling down, falling down

Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940

Enjoy with us..
https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
watchTowr Labs

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)

Hello! Yes, it's all a disaster again! Let's get this party started: 0:00 /0:12 1× No comments today, so imagine this: * We wrote something that we find very funny, * Nobody else gets it, * But everyone humors us Just like a typical watchTowr Labs blog introduction. As

14
4
15
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

What number CitrixBleed are we on?

Join us, yet again, for part 2 of our analysis of Citrix NetScaler CVE-2026-3055 - which now appears to be multiple vulnerabilities bundled into one.

Sigh.

https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2

labs.watchtowr.com
16
0
11
0
Open post
watchTowr @watchTowr@infosec.exchange
· 8mo ago

Someone knows Bash disgustingly well, and we love it.

Here's our analysis of the Ivanti EPMM Pre-Auth RCE vulnerabilities - CVE-2026-1281 & CVE-2026-1340.

This research fuels our technology, enabling our clients to accurately determine their exposure.

https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340

labs.watchtowr.com
24
0
21
1
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

speak next week friends

15
3
3
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

Happy weekend! Enjoy our analysis of CVE-2026-3055 - yet another 'Memory Overread' vulnerability in Citrix NetScaler appliances.

https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread

labs.watchtowr.com
12
0
7
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

🫡 We’re back.

Today, we’re publishing vulnerabilities we discovered, disclosed, and chained to achieve pre-auth RCE against Progress ShareFile.

Enjoy the journey with us, while you sob into your hands 🫠

https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
watchTowr Labs

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)

If you squint and look at the CISA KEV list, you might think it's made up exclusively of vulnerabilities in file transfer solutions. While this would be wrong (and you shouldn’t squint, it’s bad for your eyes), file transfer solutions do play a decent role in the

11
2
11
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

ugh, speak soon

11
3
2
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

while we’re eating our best writing crayons and using finger paint to finish our latest research, we’ve decided to take this opportunity to share research from the archives with new followers 🙂

happy Friday… for now 🥹

https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/

(Yes this is not new don’t @ us)

labs.watchtowr.com
11
1
4
0
Open post
watchTowr @watchTowr@infosec.exchange
· 4mo ago

CVE-2026-0265, the PAN-OS auth bypass (when Cloud Auth Services are enabled) was fun to reproduce and load into the watchTowr Platform.

Our friends @ @HacktronAI are publishing their analysis this week, so we won’t be publishing. Looking forward to it 🚀

6
0
6
0
Open post
watchTowr @watchTowr@infosec.exchange
· 8mo ago

Earlier this month, we reported a zero-day auth. bypass in the SmarterTools SmarterMail email solution.

Someone has reversed the patch (released on 15th Jan) and begun exploiting it in the wild.

Read our analysis and please, ASSUME BREACH + PATCH NOW.

https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/

labs.watchtowr.com
16
0
13
1
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

In 2025, we achieved pre-auth RCE against another solution in a ransomware gang favourite category. Today, we finally click publish.

Join us as we walk through a chain of vulnerabilities we identified in BMC’s FootPrints ITSM solution.

Enjoy!

https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
watchTowr Labs

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)

SolarWinds. Ivanti. SysAid. ManageEngine. Giants of the KEV world, all of whom have ITSM side-projects. ITSMs, as a group of solutions, have played pivotal roles in numerous ransomware gang campaigns - not only do they represent code running on a system, but they hold a significant amount of sensitive information.

10
0
9
0
Open post
watchTowr @watchTowr@infosec.exchange
· 5mo ago
5
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 3mo ago
What do we even say at this point? CVE-2026-8451, a zero-day Memory Overread that watchTowr Labs identified in Citrix NetScaler appliances in March, has just been publicly disclosed with patches. We're not done yet... speak soon... ;-) https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451
labs.watchtowr.com
2
2
2
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

watchTowr Intel is detecting active reconnaissance against NetScalers for CVE-2026-3055 through our Attacker Eye honeypot network.

Exploitation is likely imminent. Patch now.

watchTowr clients already have access to internal mechanisms to confidently identify their exposure.

5
0
2
0
Open post
watchTowr @watchTowr@infosec.exchange
· 7mo ago

Can you feel it too?

Join us today for our analysis of Juniper's recent pre-auth RCE - CVE-2026-21902 - affecting a very specific set of devices. Curious?

https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/

labs.watchtowr.com
6
0
4
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

It's Monday! We are currently rapidly reacting to CVE-2026-3055 - yet another unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances.

Active watchTowr Platform clients have been made aware of their exposure - reach out for support.

5
0
6
0
Open post
watchTowr @watchTowr@infosec.exchange
· 7mo ago

we're stuck in a blizzard, which means one thing - a watchTowr Labs blogpost is imminent.

in other news, we're at WT-2026-0030 for "impactful 0days reported in 2026"
https://labs.watchtowr.com/disclosed-vulnerabilities/

later, nerdz

Disclosed Vulnerabilities
watchTowr Labs

Disclosed Vulnerabilities

Our Labs & Research teams identify, validate, and responsibly disclose security vulnerabilities across widely deployed enterprise software, cloud services, and edge devices. WT ID Title CVE ID Published WT-2026-0151 Unpublished Unpublished Unpublished WT-2026-0150 Unpublished Unpublished Unpublished WT-2026-0149 Exim PROXYv2 Short-Read Uninitialised-Stack Disclosure CVE-

6
0
1
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

🚨The watchTowr Platform has autonomously deployed Active Defense mitigation rules into client envs for the currently exploited in-the-wild Fortinet FortiClient EMS zero-day, now tracked as CVE-2026-35616.

If you need support, please reach out directly or via our website.

4
0
1
0
Open post
watchTowr @watchTowr@infosec.exchange
· 5mo ago

We are currently rapidly reacting to cPanel Authentication Bypass Vulnerability, a security flaw that allows attackers to bypass authentication mechanisms affecting cPanel & WHM.
Active watchTowr Platform clients have been made aware of their exposure. Reach out for support.

3
0
3
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

The watchTowr team will be at VulnCon in Scottsdale next week!

Come find us to discuss how the watchTowr Platform, our Preemptive Exposure Management technology, helps organizations rapidly react to emerging threats, validate real-world exposure, and mitigate risk.

3
0
1
0
Open post
watchTowr @watchTowr@infosec.exchange
· 9mo ago

And, we're back - analyzing CVE-2025-52691, a pre-auth RCE in SmarterTools SmarterMail mail server solution.

Speak soon (:^)) and enjoy..

https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/

Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)
watchTowr Labs

Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)

Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that occurs every January, we’re back from Christmas and idle hands, idle minds, yada yada. In December, we were alerted to a vulnerability in SmarterTools’ SmarterMail solution, accompanied by an advisory from Singapore’s

6
1
4
1
Open post
watchTowr @watchTowr@infosec.exchange
· 8mo ago

🚨 The watchTowr team is rapidly reacting to CVE-2026-1281 & CVE-2026-1340 - unauth RCE vulnerabilities within Ivanti's Endpoint Manager Mobile (EPMM).

Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr website for support.

5
1
3
1
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

Rapid reaction gets you ahead. 6 days before CISA added CVE-2026-3055 to KEV, a Citrix NetScaler Memory Overread (CitrixBleed++) vulnerability, watchTowr clients were aware of their exposure.

Reach out via our website if you need support.

3
0
1
0
Open post
watchTowr @watchTowr@infosec.exchange
· 5mo ago

Rapid reaction gets you ahead.

1 day before CISA added CVE-2026-41940 to KEV, an Authentication Bypass vulnerability in cPanel & WHM, watchTowr clients were aware of their exposure.

Reach out via our website if you need support.

2
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

What's new is old, and what's old is new - as is relentlessly proven.

Join us in our analysis of CVE-2026-32746, the recent pre-auth RCE in inteutils' Telnetd.

Speak soon.

https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746

labs.watchtowr.com
3
0
8
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago
Replying to
@Viss@mastodon.social
2
1
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

@cR0w@infosec.exchange we don’t eat red

2
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 9mo ago

🎄 As we near Christmas, on behalf of the watchTowr team, we want to wish all of our friends, industry colleagues, clients, and partners a happy Christmas! 🚀

4
0
3
0
Open post
watchTowr @watchTowr@infosec.exchange
· 4mo ago

We're looking for new colleagues to join the phorce to work on "Project Red", our autonomous, LLM-driven N-day reproduction and 0-day discovery capability.

We're having fun, we promise ;-)

https://careers.watchtowr.com/jobs/7629309-ai-vulnerability-research-engineer

careers.watchtowr.com
1
0
3
1
Open post
watchTowr @watchTowr@infosec.exchange
· 7mo ago
Replying to
@raptor@infosec.exchange https://www.youtube.com/watch?v=RecCK7W7ZAY

64 Zoo Lane song

2
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 5mo ago

Rapid reaction gets you ahead. 67 days before CISA added CVE-2026-21643 (Fortinet FortiClientEMS SQL Injection) to KEV, watchTowr clients were aware of their exposure.

Reach out via our website if you need support.

1
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

@da_667@infosec.exchange

1
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 3mo ago
We're back, analyzing CVE-2026-8037, a pre-auth RCE in Progress' Kemp LoadMaster appliance. https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/ Speak soon...
labs.watchtowr.com
0
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 6mo ago

Rapid reaction gets you ahead. 4 days before CISA added CVE-2026-33017 (Langflow RCE) to KEV, watchTowr clients were already aware of their exposure.

Reach out via our website (watchTowr.com) if you need support.

0
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 3mo ago
Replying to
@tehfishman@ioc.exchange thx!
0
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 3mo ago
Replying to
As always, watchTowr Platform users gain industry-first access to our research ahead of publication. Research powers our Preemptive Exposure Management solution: the watchTowr Platform. https://watchtowr.com
watchtowr.com
0
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 1w ago
Replying to
Read the research behind headlines like this: https://watchtowr.com
watchtowr.com
0
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 2mo ago
Replying to
This capability is leveraged every day to get organizations leveraging the watchTowr Platform ahead of emerging threats. Reach out to learn more via our website. https://watchtowr.com
watchtowr.com
0
0
0
0
Open post
watchTowr @watchTowr@infosec.exchange
· 2mo ago
Replying to
This is what we do every day. Reach out to learn more via our website. https://watchtowr.com/demo/
watchtowr.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:58:46 UTC