Glassdoor, a website for job hunting and posting anonymous company reviews, has resolved a critical issue that could be exploited to take over accounts. Bug bounty researcher "Tabahi" (ta8ahi) found ...
Koi Security uncovered malware campaign hijacking 500,000+ VKontakte accounts via Chrome extensions Add-ons auto-subscribed victims to attacker’s VK groups (1.4M members), manipulated CSRF tokens, ...
The two critical cross-site request forgery flaws in the online learning non-profit Khan Academy have been resolved. Two critical cross-site request forgery (CSRF) flaws in educational non-profit Khan ...
Has anyone seen any problems with Rails' CSRF protection failing on iPhones?<BR><BR>We've had a couple of reports from users who're are seeing Rails' 422 "change rejected" page, and I can only think ...