Assetnote
@assetnote
Assetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.
You might like
Our Security Researcher @softpoison_ published his first research post, reverse engineering CVE-2025-54236 (SessionReaper) - a critical unauthenticated RCE in Magento. From understanding @Blaklis_'s original discovery, we wrote up our analysis here: slcyber.io/assetnote-secu…
Our Security Research team presented on Finding Critical Vulnerabilities in Adobe Experience Manager at @BSidesCbr late last month. We’ve published our research detailing the internals of AEM and how we discovered seven CVEs ranging in criticality here: slcyber.io/assetnote-secu….
Earlier this year, our Security Research team discovered a high-risk secondary context path traversal issue in Omnissa Workspace One UEM (CVE-2025-25231). We also developed a chain to RCE on instances in the wild. You can read our detailed research here: slcyber.io/assetnote-secu…
The final research blog from @SLCyberSec's Christmas in July concerns three more critical vulnerabilities that our security researchers have uncovered in Adobe Experience Manager Forms: two paths to RCE and a pre-authentication XXE slcyber.io/assetnote-secu…
Our Security Research team at @SLCyberSec found four vulnerabilities in the quality management platform ETQ Reliance, including a critical Remote Command Execution: slcyber.io/assetnote-secu…
Sometimes, SQL injection is still possible, even when prepared statements are being used. Our researcher @hash_kitten has written up a blog post about a novel technique for SQL Injection in PDO’s prepared statements: slcyber.io/assetnote-secu…
slcyber.io
Novel SQL Injection Technique in PDO Prepared Statements
Searchlight Cyber's Security Research team details a Novel Technique for SQL Injection in PDO's Prepared Statements.
Our Security Research team at @SLCyberSec discovered a pre-authentication RCE vulnerability in Sawtooth Lighthouse Studio (CVE-2025-34300). It affects all versions up to 9.16.14. Read more here: slcyber.io/assetnote-secu…
Continuing @SLCyber’s Christmas in July posts, our Security Research team discovered a pre-authentication NTLM hash disclosure vulnerability in DNN (formerly DotNetNuke), assigned CVE-2025-52488. Read more on our blog here: slcyber.io/assetnote-secu…
For our first Christmas in July research post: How we managed to get persistent XSS on every Adobe Experience Manager Cloud instance three times! slcyber.io/assetnote-secu…
We’re trying to buck the trend of critical vulnerabilities all landing at the end of the year, much to the despair of security professionals! This July, we’ll be publishing a series of vulnerabilities across the month. Stay tuned: slcyber.io/assetnote-secu…
Our team recently used a novel technique to increase the impact of what seemed to be only a blind SSRF. This novel technique involving HTTP redirect loops and incremental status codes led to full HTTP response leakage. Read more on @SLCyberSec blog here: slcyber.io/assetnote-secu…
Our security research team discovered a critical pre-authentication SQL injection vulnerability in Halo ITSM, a popular IT support software, often externally exposed and sensitive: Read more here: slcyber.io/assetnote-secu…
Our security research team recently analyzed the authentication bypass vulnerability in Next.js (CVE-2025-29927). Our blog post details how to detect this vulnerability with more reliability. Read more here: slcyber.io/assetnote-secu…
Our security research team discovered a pre-auth RCE (CVE-2025-27218) in Sitecore XP 10.4. You can read our research here: slcyber.io/blog/sitecore-…
Our security research team discovered an authentication bypass in Palo Alto's PAN-OS management interface. Our discoveries come shortly after exploit chains were released at the end of 2024 after a deeper investigation. You can read our research here: slcyber.io/blog/nginx-apa…
We are thrilled to announce that Assetnote has been acquired by Searchlight Cyber! This is an exciting new chapter for our team as we continue our mission of providing our customers with a market-leading ASM solution. Joining forces with Searchlight Cyber means that we will be…
🛠️ Building attack surface visibility from scratch taught us a crucial lesson: DNS wildcard detection requires more than open-source tools. Dive into our engineering journey: Spotify: buff.ly/3MO7jZu Apple Podcasts: buff.ly/4gTsgzQ YouTube:…
Modern enterprise infrastructure isn't just cloud-centric - it's protected by WAFs and CDNs. This architectural shift creates new challenges for traditional asset discovery approaches. Understanding your entire attack surface requires adapting to these architectural realities.…
🔒 The automation challenge in security: Many orgs struggle to automate vulnerability detection safely. Our solution? Finding the sweet spot: - Automated discovery - Proven exploitability - Zero disruption - Safe execution Learn how we make it work 🎧 Spotify:…
What looks like a niche vulnerability in one attack surface becomes a pattern when you look across thousands. That's the power of automated depth in modern ASM. Listen to our full discussion: Spotify: buff.ly/3YN4H3D Apple Podcasts: buff.ly/3TuyLzg YouTube:…
United States Trends
- 1. Good Saturday 18.9K posts
- 2. Wemby 43.6K posts
- 3. Draymond 21K posts
- 4. Steph 84.5K posts
- 5. #PerayainEFW2025 141K posts
- 6. Spurs 35.5K posts
- 7. #Truedtac5GXWilliamEst 186K posts
- 8. FAYE ATTENDS SILHOUETTE EFW 136K posts
- 9. Massie 64.1K posts
- 10. PERTHSANTA JOY KAMUTEA 611K posts
- 11. #NEWKAMUEVENTxPerthSanta 610K posts
- 12. Warriors 60.4K posts
- 13. Clemson 11.5K posts
- 14. Bubba 62.8K posts
- 15. Marjorie Taylor Greene 56.2K posts
- 16. Zack Ryder 17.8K posts
- 17. Aaron Fox 2,819 posts
- 18. Alignerz 197K posts
- 19. #DubNation 2,288 posts
- 20. Harden N/A
You might like
-
PortSwigger Research
@PortSwiggerRes -
publiclyDisclosed
@disclosedh1 -
Frans Rosén
@fransrosen -
James Kettle
@albinowax -
Brett Buerhaus
@bbuerhaus -
XSS Payloads
@XssPayloads -
ProjectDiscovery
@pdiscoveryio -
Mastering Burp Suite Pro
@MasteringBurp -
Pentester Land
@PentesterLand -
Nuclei by ProjectDiscovery
@pdnuclei -
shubs
@infosec_au -
Bug Bounty Reports Explained
@gregxsunday -
Yassine Aboukir 🐐
@Yassineaboukir -
Nicolas Grégoire
@Agarri_FR -
payloadartist
@payloadartist
Something went wrong.
Something went wrong.