WAF

Blog Archive Tag

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines
WAF
  • Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice

    Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice

    By Ryan Chaplin Ryan Chaplin takes an in-depth look at how attackers can use unsafe directives to bypass CSP, notably in Google Tag Manager, and how to remediate the issue. February 10, 2026
  • HTTP/1.1 Security News: What You Can Do Now

    HTTP/1.1 Security News: What You Can Do Now

    By Jason Taylor A recent Portswigger white paper on HTTP/1.1 highlights critical security issues. If you use old products that still require it, here’s what you can do. September 16, 2025