Log inSign up
Assetnote
178 posts
Assetnote profile banner
@assetnote

Assetnote

@assetnote
Assetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.
assetnote.io
Joined July 2017
0
Following
10.5K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @assetnote
    Assetnote
    @assetnote
    Jul 14
    Our research team discovered a critical pre-authentication RCE inside ServiceNow by bypassing their scripting sandbox (CVE-2026-6875). You can read more here:
    slcyber.io
    Smashing the ServiceNow Sandbox – Pre Authentication RCE
    Searchlight Cyber researchers discover a second pre-auth RCE in ServiceNow (CVE-2026-6875) by escaping the script sandbox via a JavaScript gadget chain, allowing full instance compromise without...
    1
  • @assetnote
    Assetnote
    @assetnote
    May 18
    Our security research team discovered a pre-authentication arbitrary file read as root in cPanel (CVE-2026-29205) — a path traversal in cpdavd that we made exploitable by abusing Dovecot's + alias handling to create attacker-controlled directory names on disk. We've updated
    https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205
    2
  • @assetnote
    Assetnote
    @assetnote
    May 5
    Our team discovered a vulnerability in Salesforce Marketing Cloud that allowed us to leak PII of subscribers and emails sent through SFMC, without any auth. Assigned CVE-2026-22585, CVE-2026-22586, CVE-2026-22582, CVE-2026-22583, CVE-2026-2298. Read our writeup here:
    slcyber.io
    Salesforce Marketing Cloud: Arbitrary Email Read via Weak Crypto
    Assetnote discovers a vulnerability in Salesforce Marketing Cloud allowing arbitrary email reads by exploiting weak legacy cryptographic primitives.
  • @assetnote
    Assetnote
    @assetnote
    Apr 30
    We've released a high fidelity detection technique for CVE-2026-41940 (cPanel/WHM auth bypass). You can find the research post here: slcyber.io/research-cente… and the tool here: github.com/assetnote/cpan… All other scanners and detection mechanisms so far will lead to false negatives.
    2
  • @assetnote
    Assetnote
    @assetnote
    Mar 26
    Our team reverse engineered the Magento PolyShell pre-auth RCE - actively exploited in the wild. No auth needed to land a PHP webshell. RCE depends on server config, but the file persists regardless. Props to @sansecio for the heads up. slcyber.io/research-cente… @SLCyberSec
    Image
    Made with AI
Advertisement
Advertisement