Security Recommendations

Get actionable cybersecurity advice from Raxis experts. Explore best practices, tips, and recommendations to strengthen your organization’s security.

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines

Articles Categorized as Security Recommendations

  • BeyondTrust RCE Vulnerability Exploited: Critical 9.9 CVSS Flaw Under Active Attack
    BeyondTrust RCE Vulnerability Exploited: Critical 9.9 CVSS Flaw Under Active Attack
    While BeyondTrust patched cloud-hosted Remote Support customers earlier this month, on-premises deployments of BeyondTrust must manually patch to remediate.
    Read More
  • Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice
    Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice
    Ryan Chaplin takes an in-depth look at how attackers can use unsafe directives to bypass CSP, notably in Google Tag Manager, and how to remediate the issue.
    Read More
  • CVE-2025-59886 Eaton Exploit Code Published
    CVE-2025-59886 Eaton Exploit Code Published
    With exploit code available for the vulnerabilities in Eaton’s xComfort Ethernet Communication Interface, Jason Taylor recommends replacing or isolating.
    Read More
  • Publicly Accessible Database Discovered Hosting 149 Million Credentials
    Publicly Accessible Database Discovered Hosting 149 Million Credentials
    Andrew Trexler looks at a recently discovered public database of stolen usernames and passwords and what you can do now to protect your access and information.
    Read More
  • The Growing Threat: Attackers Using GitHub Repositories as Malware Staging Mechanisms
    The Growing Threat: Attackers Using GitHub Repositories as Malware Staging Mechanisms
    Recent attacks, including GitVenom and Lumma Stealer, underscore the threat of Attackers using GitHub repositories as malware staging mechanisms.
    Read More
  • CVE‑2020‑12812 and Why It’s Still an Issue Five Years Later
    CVE‑2020‑12812 and Why It’s Still an Issue Five Years Later
    Principal Penetration Tester Scottie Cole explains why Fortinet released a new security advisory about CVE‑2020‑12812 and what your organization should check.
    Read More