Jake

21 posts

Jake

Jake

@inkmoro

Principal Security Researcher @ watchTowr

United Kingdom Katılım Kasım 2021
523 Takip Edilen225 Takipçiler
Jake
Jake@inkmoro·
👀
ART
0
0
0
258
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
The watchTowr team has broken down the Oracle EBS unauth RCE exploit chain (tagged as CVE-2025-61882). Important to note: it is not one vulnerability, but multiple chained together. As always, we'll share more soon.
watchTowr tweet media
English
6
84
334
31.9K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
Are we bleeding out? Enjoy our analysis of CitrixBleed 2, aka CVE-2025-5777 - the "new" Citrix NetScaler Memory Leak vulnerability. We've been using this mechanism to identify vulnerable systems, and hope it helps the teams that need it.. enjoy! labs.watchtowr.com/how-much-more-…
English
6
75
205
22.5K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
8 million requests, $400 later - we’re back. 🚀 We have demonstrated supply chain attacks that could have allowed us to trivially compromise critical infra. networks, including .gov, .mil, and more. This is real Attack Surface Management. labs.watchtowr.com/8-million-requ…
English
11
90
272
56.1K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
watchTowr Labs is back - this time, reproducing the ITW exploited Cleo vulnerabilities (CVE-2024-50623). Here’s a teaser before we drop the PoC 😀
watchTowr tweet media
English
6
42
189
31.1K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
👀 we’ve watched APTs recently ravage lawful interception systems, and wanted our own capabilities… Join us on a journey today into Mitel’s MiCollab - that originally started to reproduce CVE-2024-35286, and quickly unravelled into more… labs.watchtowr.com/where-theres-s…
English
0
37
99
7.7K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
in today's 'no way, is it real?' we found out that Palo Alto's PAN-OS CVE-2024-0012 and CVE-2024-9474 were the equivalents of saying 'turn off auth and give me a shell'. Enjoy! labs.watchtowr.com/pots-and-pans-…
English
12
168
430
101.6K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
hop skip jump over to our latest blog post - analysing Fortinet's FortiJump CVE-2024-47575, FortiJump-Higher (we love this name😄) and beyond (PoC included) labs.watchtowr.com/hop-skip-forti…
English
6
73
168
31.1K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
In August, watchTowr Labs hijacked parts of the global .mobi TLD - and went on to discover the mayhem that we could cause. Enjoy.... labs.watchtowr.com/we-spent-20-to…
English
9
126
344
49.5K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
Progress just un-embargoed a very closely guarded auth bypass in MOVEit Transfer's SFTP mechanism - CVE-2024-5806. We were lucky enough to receive a tip-off :-) Enjoy our analysis, we had a lot of fun. labs.watchtowr.com/auth-bypass-in…
English
7
81
177
37.8K
Jake retweetledi
Aliz (they/them pls)
Aliz (they/them pls)@AlizTheHax0r·
holy moly, replicated #CVE-2024-24919 (the checkpoint bug) and it's WAY more than the advisory states. :/
English
7
31
215
55.5K
Jake retweetledi
watchTowr
watchTowr@watchtowrcyber·
Another week, another SSLVPN RCE - this time, it's CVE-2024-3400 in Palo Alto's GlobalProtect. But, we've seen no public analysis 🙁 so, allow us.. labs.watchtowr.com/palo-alto-putt…
English
8
96
243
46.1K