Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

watchTowr

@watchTowr@infosec.exchange
  • Open on infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

0 Followers
0 Following
45 Posts
Joined December 05, 2024
Website:
https://watchtowr.com

Posts

Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jul 23, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Replying to @watchTowr@infosec.exchange
This capability is leveraged every day to get organizations leveraging the watchTowr Platform ahead of emerging threats. Reach out to learn more via our website. https://watchtowr.com
0
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jul 23, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Introducing Project Red - the autonomous vulnerability reproduction capability behind the watchTowr Platform. Project Red reproduced wp2shell in 22 minutes. Active Defense deployed mitigations to clients 11 minutes later. Before in-the-wild exploitation began.
0
1
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jul 21, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Replying to @watchTowr@infosec.exchange
This is what we do every day. Reach out to learn more via our website. https://watchtowr.com/demo/
0
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jul 21, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
wp2shell: 22 minutes to reproduce with Project Red. 11 minutes later, Active Defense pushed mitigations. All before in-the-wild exploitation began. A pre-auth RCE in WordPress: disclosure to exploitation in hours. Preemptive Exposure Management, built to outpace attackers.
0
1
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jul 02, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Replying to @watchTowr@infosec.exchange
As always, watchTowr Platform users gain industry-first access to our research ahead of publication. Research powers our Preemptive Exposure Management solution: the watchTowr Platform. https://watchtowr.com
0
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jul 02, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
It's hot, and we're desperate - so we turned to Adobe ColdFusion and APSB26-68, our favorite Security Bulletin. Enjoy, and speak soon... ;-) https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza
1
0
1
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jun 30, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Replying to @tehfishman@ioc.exchange
@tehfishman@ioc.exchange thx!
0
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jun 30, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
What do we even say at this point? CVE-2026-8451, a zero-day Memory Overread that watchTowr Labs identified in Citrix NetScaler appliances in March, has just been publicly disclosed with patches. We're not done yet... speak soon... ;-) https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451
2
2
2
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jun 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
We're back, analyzing CVE-2026-8037, a pre-auth RCE in Progress' Kemp LoadMaster appliance. https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/ Speak soon...
0
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · May 21, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

We're looking for new colleagues to join the phorce to work on "Project Red", our autonomous, LLM-driven N-day reproduction and 0-day discovery capability.

We're having fun, we promise ;-)

https://careers.watchtowr.com/jobs/7629309-ai-vulnerability-research-engineer

1
0
3
1
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · May 19, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

CVE-2026-0265, the PAN-OS auth bypass (when Cloud Auth Services are enabled) was fun to reproduce and load into the watchTowr Platform.

Our friends @ @HacktronAI are publishing their analysis this week, so we won’t be publishing. Looking forward to it 🚀

Your browser does not support the video tag.
6
0
6
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · May 06, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Rapid reaction gets you ahead.

1 day before CISA added CVE-2026-41940 to KEV, an Authentication Bypass vulnerability in cPanel & WHM, watchTowr clients were aware of their exposure.

Reach out via our website if you need support.

2
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

The Internet is falling down, falling down, falling down

Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940

Enjoy with us..
https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
watchTowr Labs

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-202

Hello! Yes, it's all a disaster again! Let's get this party started: 0:00 /0:12 1× No comments today, so imagine this: * We wrote something that we find

14
4
15
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

We are currently rapidly reacting to cPanel Authentication Bypass Vulnerability, a security flaw that allows attackers to bypass authentication mechanisms affecting cPanel & WHM.
Active watchTowr Platform clients have been made aware of their exposure. Reach out for support.

3
0
3
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
5
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 16, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

whoever bought http://a-fun-hostname-for-f5-to-mark-as-an-ioc.com and redirected it to our blog post - please reach out, we love you

28
0
12
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 16, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Rapid reaction gets you ahead. 67 days before CISA added CVE-2026-21643 (Fortinet FortiClientEMS SQL Injection) to KEV, watchTowr clients were aware of their exposure.

Reach out via our website if you need support.

1
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 09, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

The watchTowr team will be at VulnCon in Scottsdale next week!

Come find us to discuss how the watchTowr Platform, our Preemptive Exposure Management technology, helps organizations rapidly react to emerging threats, validate real-world exposure, and mitigate risk.

3
0
1
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 04, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

🚨The watchTowr Platform has autonomously deployed Active Defense mitigation rules into client envs for the currently exploited in-the-wild Fortinet FortiClient EMS zero-day, now tracked as CVE-2026-35616.

If you need support, please reach out directly or via our website.

4
0
1
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Apr 02, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

🫡 We’re back.

Today, we’re publishing vulnerabilities we discovered, disclosed, and chained to achieve pre-auth RCE against Progress ShareFile.

Enjoy the journey with us, while you sob into your hands 🫠

https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
watchTowr Labs

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699

If you squint and look at the CISA KEV list, you might think it's made up exclusively of vulnerabilities in file transfer solutions. While this would be wrong (and you shouldn’t squint, it’s bad for

11
2
11
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 30, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Rapid reaction gets you ahead. 6 days before CISA added CVE-2026-3055 to KEV, a Citrix NetScaler Memory Overread (CitrixBleed++) vulnerability, watchTowr clients were aware of their exposure.

Reach out via our website if you need support.

3
0
1
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

What number CitrixBleed are we on?

Join us, yet again, for part 2 of our analysis of Citrix NetScaler CVE-2026-3055 - which now appears to be multiple vulnerabilities bundled into one.

Sigh.

https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2

16
0
11
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Replying to @Viss@mastodon.social
@Viss@mastodon.social
2
1
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

ugh, speak soon

11
3
2
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 28, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Happy weekend! Enjoy our analysis of CVE-2026-3055 - yet another 'Memory Overread' vulnerability in Citrix NetScaler appliances.

https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread

12
0
7
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 28, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

@cR0w@infosec.exchange we don’t eat red

infosec.exchange

:rainbowCrow: (@cR0w@infosec.exchange) - Infosec Exchange

2
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 28, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

while we’re eating our best writing crayons and using finger paint to finish our latest research, we’ve decided to take this opportunity to share research from the archives with new followers 🙂

happy Friday… for now 🥹

https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/

(Yes this is not new don’t @ us)

We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
watchTowr Labs

We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI

Welcome back to another watchTowr Labs blog. Brace yourselves, this is one of our most astounding discoveries. Summary What started out as a bit of fun between colleagues while avoiding the Vegas h

11
1
4
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 27, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

watchTowr Intel is detecting active reconnaissance against NetScalers for CVE-2026-3055 through our Attacker Eye honeypot network.

Exploitation is likely imminent. Patch now.

watchTowr clients already have access to internal mechanisms to confidently identify their exposure.

5
0
2
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 25, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Rapid reaction gets you ahead. 4 days before CISA added CVE-2026-33017 (Langflow RCE) to KEV, watchTowr clients were already aware of their exposure.

Reach out via our website (watchTowr.com) if you need support.

0
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 23, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

It's Monday! We are currently rapidly reacting to CVE-2026-3055 - yet another unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances.

Active watchTowr Platform clients have been made aware of their exposure - reach out for support.

5
0
6
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 20, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

@da_667@infosec.exchange

infosec.exchange

da_667 (@da_667@infosec.exchange) - Infosec Exchange

1
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 20, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

~150 S3 abandoned buckets. 8M+ requests. Two months. Software updates, binaries, VMs and more.

This week, AWS rolled out namespaces for new S3 buckets - finally.

This is why offensive security research is so important - to move the needle.

https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/

8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateur
watchTowr Labs

8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateur

Surprise surprise, we've done it again. We've demonstrated an ability to compromise significantly sensitive networks, including governments, militaries, space agencies, cyber security companies, suppl

38
6
24
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 20, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

speak next week friends

15
3
3
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 19, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

What's new is old, and what's old is new - as is relentlessly proven.

Join us in our analysis of CVE-2026-32746, the recent pre-auth RCE in inteutils' Telnetd.

Speak soon.

https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746

3
0
8
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 18, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

In 2025, we achieved pre-auth RCE against another solution in a ransomware gang favourite category. Today, we finally click publish.

Join us as we walk through a chain of vulnerabilities we identified in BMC’s FootPrints ITSM solution.

Enjoy!

https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
watchTowr Labs

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains

SolarWinds. Ivanti. SysAid. ManageEngine. Giants of the KEV world, all of whom have ITSM side-projects. ITSMs, as a group of solutions, have played pivotal roles in numerous ransomware gang campaigns

10
0
9
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 18, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

speak soon

29
3
5
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Mar 03, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Can you feel it too?

Join us today for our analysis of Juniper's recent pre-auth RCE - CVE-2026-21902 - affecting a very specific set of devices. Curious?

https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/

Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)
watchTowr Labs

Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Au

On today’s ‘good news disguised as other things’ segment, we’re turning our gaze to CVE-2026-21902 - a recently disclosed “Incorrect Permission Assignment for Critical Resource” vulnerability affectin

6
0
4
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Feb 25, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

we're stuck in a blizzard, which means one thing - a watchTowr Labs blogpost is imminent.

in other news, we're at WT-2026-0030 for "impactful 0days reported in 2026"
https://labs.watchtowr.com/disclosed-vulnerabilities/

later, nerdz

Disclosed Vulnerabilities
watchTowr Labs

Disclosed Vulnerabilities

Our Labs & Research teams identify, validate, and responsibly disclose security vulnerabilities across widely deployed enterprise software, cloud services, and edge devices. WT ID Title CVE ID Pub

6
0
1
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Feb 13, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange
Replying to @raptor@infosec.exchange
@raptor@infosec.exchange https://www.youtube.com/watch?v=RecCK7W7ZAY
2
0
0
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Feb 13, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

2026, the year of the AI-driven attacker that could do back flips, they said.

Meanwhile, there's a magic number that allows Auth Bypass against Ivanti EPM (CVE-2026-1603)

something about a pledge 🙄

63
10
44
0
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jan 30, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Someone knows Bash disgustingly well, and we love it.

Here's our analysis of the Ivanti EPMM Pre-Auth RCE vulnerabilities - CVE-2026-1281 & CVE-2026-1340.

This research fuels our technology, enabling our clients to accurately determine their exposure.

https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340

24
0
21
1
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jan 29, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

🚨 The watchTowr team is rapidly reacting to CVE-2026-1281 & CVE-2026-1340 - unauth RCE vulnerabilities within Ivanti's Endpoint Manager Mobile (EPMM).

Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr website for support.

5
1
3
1
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jan 22, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

Earlier this month, we reported a zero-day auth. bypass in the SmarterTools SmarterMail email solution.

Someone has reversed the patch (released on 15th Jan) and begun exploiting it in the wild.

Read our analysis and please, ASSUME BREACH + PATCH NOW.

https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/

Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)
watchTowr Labs

Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)

Well, well, well - look what we’re back with. You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a

16
0
13
1
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Jan 08, 2026
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

And, we're back - analyzing CVE-2025-52691, a pre-auth RCE in SmarterTools SmarterMail mail server solution.

Speak soon (:^)) and enjoy..

https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/

Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)
watchTowr Labs

Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)

Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that occurs every January, we’re back from Christmas and idle hands, idle minds, yada yada. In Decembe

6
1
4
1
Open post
watchTowr
watchTowr @watchTowr@infosec.exchange · Dec 24, 2025
watchTowr
@watchTowr@infosec.exchange

watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.

infosec.exchange

🎄 As we near Christmas, on behalf of the watchTowr team, we want to wish all of our friends, industry colleagues, clients, and partners a happy Christmas! 🚀

4
0
3
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 05:25:52 UTC