Fortinet Fixes Vulnerabilities in FortiOS

Fortinet Fixes Vulnerabilities in FortiOS

Researchers have identified vulnerabilities in Fortinet FortiOS that can be used by threat actors for malicious activities. The vulnerabilities are Cross-Site scripting (XSS) and Cross-Site request forgery (CSRF) vulnerabilities. These…
Kudu SCM Vulnerable to CSRF

Kudu SCM Vulnerable to CSRF

A CSRF vulnerability impacting the source control management service Kudu could be exploited to achieve remote code execution in multiple Azure services. Kudu is the engine behind several Azure App…
F5 address CSRF and RCE vulnerabilities in BIG-IP

F5 address CSRF and RCE vulnerabilities in BIG-IP

F5 released patches for vulnerabilities affecting its BIG-IP and BIG-IQ networking devices that could result in remote code execution (RCE). The vulnerability CVE-2022-41622 leaves BIG-IP and BIG-IQ vulnerable to unauthenticated…
Grafana Vulnerability Opens Attackers invasion

Grafana Vulnerability Opens Attackers invasion

Researchers discovered a high-impact web security vulnerability in popular dashboard tool Grafana. The CSRF vulnerability tracked as CVE-2022-21703 opens the door for attackers to elevate their privileges through cross-origin attacks…
Chrome Soon Will Enable CSRF Protection

Chrome Soon Will Enable CSRF Protection

In a major work through, beginning soon chrome is deprecating direct access to private network endpoints from public websites to protect users CSRF Attack. This move is specifically designed to…
XS-Leaks in Modern Browsers

XS-Leaks in Modern Browsers

Researchers have discovered 14 new types of cross-site data leakage attacks against a number of modern web browsers, including Tor Browser, Mozilla Firefox, Google Chrome, Microsoft Edge, Apple Safari, and…
Drupal Patches Vulnerabilities

Drupal Patches Vulnerabilities

Updates released for Drupal 8.9, 9.1 and 9.2 patch five vulnerabilities that can be exploited for CSRF and access bypass issues. Three of the flaws are related to access bypass.…