Nagios XI Stored Cross-Site Scripting (XSS): CVE-2021-38156
Nagios XI Stored Cross-Site Scripting (XSS): CVE-2021-38156

Nagios is open-source network and system monitoring software. Raxis’ Matt Dunn has discovered a cross-site[…]

PRTG Network Monitor Stored Cross-Site Scripting Vulnerability (CVE-2021-29643)
PRTG Network Monitor Stored Cross-Site Scripting Vulnerability (CVE-2021-29643)

Raxis lead penetration tester Matt Dunn uncovers a new vulnerability in the PRTG Network Monitor[…]

JavaScript Execution to Display User's Cookie in an Alert Box
ManageEngine Applications Manager Stored Cross-Site Scripting Vulnerability (CVE-2021-31813)

Raxis’ lead penetration tester Matt Dunn has discovered another ManangeEngine cross-site scripting (XSS) vulnerability, this[…]

Unescaped JavaScript Tags
ManageEngine Key Manager Plus Cross-Site Scripting Vulnerability (CVE-2021-28382)

Raxis’ Lead Penetration Tester Matt Dunn discovers another cross-site scripting vulnerability in Zoho’s MangeEngine Key[…]

Cross-Site Scripting Vulnerability in ManageEngine AD Self Service Plus (CVE-2021-27956)
Cross-Site Scripting Vulnerability in ManageEngine AD Self Service Plus (CVE-2021-27956)

Raxis lead penetration tester Matt Dunn has uncovered a new cross-site scripting vulnerability in Manage[…]

Emblem of the Foreign Intelligence Service of the Russian Federation
NSA, FBI, CISA Statement on Russian SVR Activity

The US government is warning businesses to beware of vulnerabilities being exploited by the Russian[…]

How to Pull Off a Mousejacking Attack
How to Pull Off a Mousejacking Attack

Raxis demonstrates how to conduct a mousejacking attack as part of a penetration test.

Penguin with red cross
Sudo Privilege Escalation Vulnerability Discovered

Qualys has discovered and reported a serious vulnerability (CVE-2021-3156) affecting the sudo utility. Patches are[…]

Cisco with bandaids
Cisco Patches Critical Security Vulnerabilities

Cisco releases patches for some critical and high-severity vulnerabilities.

Understanding Vulnerability Management
Understanding Vulnerability Management

One of our most common findings in Raxis penetration tests is the lack of an[…]

Brian Tant, Raxis VP of Engineering
Why Network Segmentation is a Best Security Practice

Network segmentation can be an important line of defense against hackers. Raxis’ CTO Brian Tant[…]

Raxis COO, Bonnie Smyre
What to Expect When You’re Expecting a (Raxis) Penetration Test

You know you need to do penetration testing, but you’re not sure how it works.[…]