Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Reddit r/netsec

Bypassing Referer-Based CSRF with strict-origin-when-cross-origin

  • What: A method to bypass CSRF protections using Referer headers.
  • Impact: Could lead to credential theft in certain scenarios.
Read Full Article →

FAQ Questions enterprise security teams ask before partnering with AFINE for security assessments. No items found. Enterprise Security Newsletter for Banking Practical offensive security insights from banking operations, from the team making banks more secure for over 10 years. Be the first to know when we find something worth your attention. By clicking Subscribe you're confirming that you agree with our Privacy Policy . Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. Related posts Eager to see more pen-testing goodness? Check out some of our other blog posts. Category Stealing Passwords via HTML Injection Under a Strict CSP Turning a reflected HTML injection under a strict CSP into full credential theft by chaining Chrome's password autofill with Referer header leakage. Rafał Wójcicki July 21, 2026 • 10 min read Category How to Choose a Penetration Testing Company - The 2026 Buyer's Checklist A five-stage checklist for evaluating and choosing a penetration testing company - scope qualification, vendor vetting, proposal scoring and report anatomy. Paweł Woyke May 7, 2026 • 9 min read Category Time of Check Time of Use (TOCTOU): Anatomy of a Race Condition in GNU sed CVE-2026-5958 is a textbook TOCTOU bug that sat inside GNU sed's --follow-symlinks path for two decades. This post walks through the race at the syscall level and the fix shipped in sed 4.10. Marcin Wyczechowski Michał Majchrowicz May 1, 2026 • 9 min read View all Cookie Settings We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you. See our Privacy Policy Reject all I want to choose Accept All Functionality Analytics Storage Ad Storage Ad User Data Ad Personalisation Personalization Storage Security Storage Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. Accept selection

Share this article