watchTowr Profile Banner
watchTowr Profile
watchTowr

@watchtowrcyber

Followers
3,693
Following
12
Media
37
Statuses
157

Your very own APT group, in an Attack Surface Management solution.

Joined November 2020
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@watchtowrcyber
watchTowr
2 months
we're hiring globally, on our crusade to hack the planet
Tweet media one
0
9
46
@watchtowrcyber
watchTowr
3 months
Tweet media one
13
136
928
@watchtowrcyber
watchTowr
2 months
speak soon. CVE-2024-4577, Argument Injection in PHP-CGI
Tweet media one
8
189
926
@watchtowrcyber
watchTowr
6 months
Even Ivanti don’t use Ivanti
Tweet media one
8
46
290
@watchtowrcyber
watchTowr
5 months
Here's our PoC for the Connectwise ScreenConnect Auth Bypass: The vuln is the definition of trivial and thus we won't release any analysis. Not sure what we would share - "Add a / and you too can pwn the world"?
Tweet media one
7
83
254
@watchtowrcyber
watchTowr
5 months
we are truly shocked to hear about a CVSS 10.0 vuln in ConnectWise shocked
Tweet media one
4
44
236
@watchtowrcyber
watchTowr
1 month
Progress just un-embargoed a very closely guarded auth bypass in MOVEit Transfer's SFTP mechanism - CVE-2024-5806. We were lucky enough to receive a tip-off :-) Enjoy our analysis, we had a lot of fun.
7
85
185
@watchtowrcyber
watchTowr
6 months
yes you read it right - trying to reproduce this weeks Ivanti CVEs has led us into further 0days on a fully patched Ivanti SSLVPN device We’ll report; but our 90 day policy will restrict any further sharing
11
61
178
@watchtowrcyber
watchTowr
2 months
it's not Friday, but it's def Nday - ha ha ha 🫠 Check Point's very friendly 'info disclosure' needed a little bit of attention, and thus we've flung our analysis onto the Internet for CVE-2024-24919 - enjoy!
3
57
159
@watchtowrcyber
watchTowr
3 months
speak soon friends
Tweet media one
5
16
111
@watchtowrcyber
watchTowr
6 months
🚀Ivanti Connect Secure CVE-2024-22024 we've released our watchTowr Labs blog post, containing a little bit of commentary, our analysis, and an unweaponized reproducer for this vulnerability. Enjoy the read, we're excited to share more research soon!
6
55
109
@watchtowrcyber
watchTowr
5 months
Today, we take on IBM - discussing unauth Remote Code Execution vulns we recently disclosed in IBM's Operational Decision Manager These bugs, and their PoCs, require more letters than the mighty '/' - but hopefully still an enjoyable read More soon....
3
38
88
@watchtowrcyber
watchTowr
7 months
🚀 We have reproduced both in-the-wild exploited Ivanti zero-days (CVE-2023-46805 & CVE-2024-21887) 🥷 We've released some of our research in this blogpost - but rest assured, full exploit chain details are heavily redacted (for now) 🙂
0
36
79
@watchtowrcyber
watchTowr
6 months
Tweet media one
1
12
74
@watchtowrcyber
watchTowr
6 months
Tweet media one
0
16
57
@watchtowrcyber
watchTowr
10 months
we're back - causing trouble with more enterprise-grade firewalls :-) join us on the journey...
Tweet media one
1
12
42
@watchtowrcyber
watchTowr
4 months
0
12
39
@watchtowrcyber
watchTowr
4 months
0
6
39
@watchtowrcyber
watchTowr
2 months
Full-disclosure works. "Moving forward, for vulnerabilities triaged as High or Critical severity, we commit to completing remediation and releasing fixes within 45 days. " 🫡
0
3
33
@watchtowrcyber
watchTowr
10 months
The world is ablaze with discussions around the recently revealed Exim 0days. What's going on, is the sky falling? Are there really 3.5 million Exim servers vulnerable? Let's tackle each bug in turn and see. A thread.. 1/N 🧵
1
12
34
@watchtowrcyber
watchTowr
2 months
We’re thrilled to welcome our newest watchTowr Labs member, @SinSinology 🚀 The mayhem will continue until the planet is hacked 🫡
@SinSinology
SinSinology
2 months
Since @VMwareSRC has been ignoring me, I've decided to take the vengeance route🩸
Tweet media one
12
18
183
0
4
32
@watchtowrcyber
watchTowr
4 months
a good time to mention - we're hiring Vuln Researchers to join our watchTowr Labs team in SG and UK, to do 0day/Nday research that goes into our ASM product and sometimes on our blog. No shady vuln sales here.
2
8
28
@watchtowrcyber
watchTowr
6 months
you know it's a Friday when you suddenly have a reproducer 👀 #ivanti
1
4
25
@watchtowrcyber
watchTowr
6 months
nevermind sorry, it's just more Ivanti 0day on a fully patched appliance - no reproducer yet 😢
1
8
25
@watchtowrcyber
watchTowr
4 months
something something sophistication levels only achievable by a nation-state something something string concat command injection something something
3
3
25
@watchtowrcyber
watchTowr
6 months
We would like to take this opportunity to highlight the obvious If we did this, who else did this
0
6
22
@watchtowrcyber
watchTowr
5 months
what's that sound? is it the sound of another earth-shattering world-ending single-character PoC? or is it a new watchTowr Labs blogpost? let's see...
2
3
20
@watchtowrcyber
watchTowr
1 month
speak soon
2
1
19
@watchtowrcyber
watchTowr
6 months
CVE-2024-22024
3
6
19
@watchtowrcyber
watchTowr
5 months
“hear me out…. if we release more PoCs…. then we can get more bones…”
Tweet media one
1
1
18
@watchtowrcyber
watchTowr
9 months
🫡 join watchTowr Labs on our latest adventure into OpenCMS - today though, we take a detour to attack exploitable dependencies 🚀 Dive into our technical analysis, our analysis approach, and PoCs 🙂
0
5
19
@watchtowrcyber
watchTowr
6 months
watchTowr is expanding globally! @_bytefantastic and @inkmoro have joined our Europe Labs team, based in the UK, and are visiting the Singapore team this week! 🚀🚀🚀🚀🚀🚀🚀🚀🚀🚀
Tweet media one
1
4
18
@watchtowrcyber
watchTowr
1 month
reporters, please stop emailing us to ask who d4v1d_bl41ne is - it’s a joke
2
2
17
@watchtowrcyber
watchTowr
1 month
we promise to never make jokes again
Tweet media one
1
0
17
@watchtowrcyber
watchTowr
4 months
a healthy obsession with SSLVPNs, memes, and trolling are good-to-haves
0
0
17
@watchtowrcyber
watchTowr
10 months
Our brief technical analysis of the sky-is-falling #exim #0days is now live 🚀 Read along with the @watchtowrcyber Labs team to understand CVE-2023-42115! #attacksurfacemanagement #vulnresearch #watchtowr
@watchtowrcyber
watchTowr
10 months
The world is ablaze with discussions around the recently revealed Exim 0days. What's going on, is the sky falling? Are there really 3.5 million Exim servers vulnerable? Let's tackle each bug in turn and see. A thread.. 1/N 🧵
1
12
34
0
4
14
@watchtowrcyber
watchTowr
4 months
quick update
Tweet media one
2
3
14
@watchtowrcyber
watchTowr
7 months
🚀 back in September, while analysing Juniper n-days, we stumbled into... more Read our latest dive into Juniper code, where we discuss the unauthenticated file read > root password hash disclosure vulnerability that we discovered in Juniper J-Web
1
12
14
@watchtowrcyber
watchTowr
11 months
When software is introduced as the solution used by “Enterprises and Governments” worldwide - naturally, attention is drawn 😀 Join us on our journey to RCE in Orbeon Forms
0
6
14
@watchtowrcyber
watchTowr
7 months
Tweet media one
0
0
13
@watchtowrcyber
watchTowr
3 months
we are serious - come join us hack the planet
@watchtowrcyber
watchTowr
4 months
a good time to mention - we're hiring Vuln Researchers to join our watchTowr Labs team in SG and UK, to do 0day/Nday research that goes into our ASM product and sometimes on our blog. No shady vuln sales here.
2
8
28
0
2
12
@watchtowrcyber
watchTowr
2 months
@x1m_martijn There are credits all over our Twitter, blogpost and GitHub repo to @orange_8361 for this vuln 🫡
2
0
10
@watchtowrcyber
watchTowr
2 months
speak soon
0
2
11
@watchtowrcyber
watchTowr
5 months
Tweet media one
0
1
10
@watchtowrcyber
watchTowr
2 months
1
3
9
@watchtowrcyber
watchTowr
2 years
🚀🚀🚀
Tweet media one
0
1
9
@watchtowrcyber
watchTowr
6 months
as always; our clients - users of the watchTowr Platform, our ASM and CART technology - benefit from early identification of vulnerable appliances across their attack surface so that proactive actions can be taken
0
0
9
@watchtowrcyber
watchTowr
2 years
1x Enterprise IAM vs 1x Slanty Line
Tweet media one
0
3
8
@watchtowrcyber
watchTowr
10 months
is the curl CVE-2023-38545 as bad as suggested? No. No, it's not. Read our rapid analysis to understand more, and see which stars need to align for this vulnerability to be real-world-usable.
0
3
8
@watchtowrcyber
watchTowr
6 months
ahem?
Tweet media one
3
1
8
@watchtowrcyber
watchTowr
5 months
Tweet media one
1
4
8
@watchtowrcyber
watchTowr
4 months
the watchTowr team will be @BlackHatEvents Asia tomorrow!
Tweet media one
0
1
8
@watchtowrcyber
watchTowr
10 months
a small clue for *maybe* next week...
Tweet media one
1
2
7
@watchtowrcyber
watchTowr
1 year
🥷 we're growing watchTowr Labs - we're on the hunt for a Principal Vulnerability Researcher! A pure research role - focused on analysing N-day and discovering 0-day vulnerabilities - full-time. 👊
Tweet media one
0
6
5
@watchtowrcyber
watchTowr
7 months
🎄 from the watchTowr team, we wish everyone a happy Christmas and a fantastic New Year! May your 2024 be full of shells, pwnage and 0dayzz We're looking forward to continuing the mayhem... see you in January! 🫡
Tweet media one
0
2
5
@watchtowrcyber
watchTowr
6 months
🚨 it all begins again - there is a new in-the-wild Ivanti SSLVPN vulnerability being exploited Ivanti have updated their original vulnerability knowledge base article to add further vulnerabilities, inc an active ITW SSRF vulnerability being used to bypass authentication
1
1
5
@watchtowrcyber
watchTowr
6 months
🐉happy Lunar New Year from the watchTowr team!
Tweet media one
0
0
4
@watchtowrcyber
watchTowr
7 months
we have more coming.. a lot more.. 😭
0
0
4
@watchtowrcyber
watchTowr
4 months
"At this point, we're onto something - we have an arbitrary value in the shape of a filename being injected into a shell command. Are we on a path to receive angry tweets again?"
0
1
4
@watchtowrcyber
watchTowr
4 months
speak soon 🫡
0
1
4
@watchtowrcyber
watchTowr
1 year
🚨 we have confirmed and reproduced the rumoured Fortinet FortiGate RCE that is embargoed until the 13th, discovered by Olympe Cyberdefense. Please patch ASAP.
Tweet media one
1
3
4
@watchtowrcyber
watchTowr
8 months
we're hiring! come and join an incredible phorce of nature as we progress on our world domination mission 🚀 if any of the roles in the picture interest you, please check out the JDs at 💪
Tweet media one
0
5
3
@watchtowrcyber
watchTowr
6 months
@GossiTheDog not even a credit? 😢
0
0
2
@watchtowrcyber
watchTowr
6 months
has been updated to detail new vulnerabilities
0
2
2
@watchtowrcyber
watchTowr
7 months
@Shadowserver awesome stuff! 🫡
0
0
2
@watchtowrcyber
watchTowr
5 months
0
0
2
@watchtowrcyber
watchTowr
3 months
@GelosSnake @ManishNeupane03 sir, the SSLVPN world moves too fast to think about vulnerabilities in terms of years
1
0
2
@watchtowrcyber
watchTowr
1 year
🥷 we've reproduced and confirmed both the triviality and impact of the CVE-2023-35078.. please patch your Ivanti/MobileIron appliances.. 😰 #attacksurfacemanagement #vulnresearch #ivanti #mobileiron #cve202335078
Tweet media one
0
1
2
@watchtowrcyber
watchTowr
11 months
🚀 The countdown begins - just 3 days to go until 44CON! We are thrilled to be sponsoring 44CON this year and we can't wait to see everyone there 🥳 We have a lot of watchTowr t-shirts to give away; please don't leave us with any! 😀 #attacksurfacemanagement #44con #london
Tweet media one
0
1
2
@watchtowrcyber
watchTowr
1 year
📦 We’re back, in part 3 of our series on discovering Docker secrets 🚀 @AlizTheHax0r lays out the overall architecture of the system used to ingest over 22,000 Docker containers: #cybersecurity #continuousautomatedredteaming #attacksurfacemanagement
Tweet media one
0
1
2
@watchtowrcyber
watchTowr
6 months
@MichTech360 no, this is not a Meraki
0
0
1
@watchtowrcyber
watchTowr
1 year
@n3c8 we've reproduced and reversed from the patches - it's bad
Tweet media one
0
1
1
@watchtowrcyber
watchTowr
10 months
First, let's look at the 'worst' - CVSS 9.8, CVE-2023-42115. Whoa! Scary. It's an out-of-bounds write that can lead to RCE. But hang on, there's a huge caveat - it only affects 'external' authentication. If you're not using that, no need to worry.
1
0
1
@watchtowrcyber
watchTowr
5 months
Customers of the watchTowr Platform benefited from a rapid response to this weakness more than 12 hours ago as part of our global and 24/7 Rapid Reaction capabilities.
0
0
1
@watchtowrcyber
watchTowr
6 months
@wdormann curious right?
0
0
1
@watchtowrcyber
watchTowr
6 months
@lawndoc Thanks, on behalf of the team
1
0
1