Cross-site request forgery is a vulnerability tracked by ThreatCluster, appearing in 13 threat clusters built from 14 intelligence report mentions.
Cross-site request forgery is a vulnerability tracked across 13 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity July 23, 2026.
CISA has warned of ongoing attacks exploiting the CVE-2008-4128 vulnerability in Cisco IOS 12.4, a cross-site request forgery flaw. This vulnerability, which has been known since 2008, allows attackers to execute…
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
Multiple vulnerabilities were identified in the Authlib library used in Ubuntu systems, specifically affecting versions 24.04 LTS and 26.04 LTS. Discovered by researchers Jay Neiva, Mauro Carrillo, and Johnny Deuss,…
Two significant vulnerabilities have been identified in Jenkins plugins, CVE-2026-48922 and CVE-2026-48925. The Jenkins Credentials Binding Plugin allows attackers to write files to arbitrary locations, potentially…
Anthropic has announced the launch of Project Glasswing, utilizing its unreleased AI model, Claude Mythos Preview, to identify and exploit thousands of critical software vulnerabilities across major operating systems…
Zenity Labs has identified a critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents. This flaw allows attackers to create a malicious AI agent within an organization by embedding instructions in a…
Recent investigations into AI browsers like Perplexity Comet and ChatGPT Atlas reveal significant security vulnerabilities, particularly prompt injection attacks. These attacks allow malicious actors to embed harmful…
GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign…
A security vulnerability has been identified in Mailman, affecting Ubuntu 20.04 LTS and 16.04 LTS. The flaw allows a remote list member or moderator to bypass CSRF token protections, enabling them to craft admin…
A critical vulnerability in Angular's HTTP Client has been identified, allowing attackers to intercept Cross-Site Request Forgery (XSRF) tokens. This flaw poses a significant risk to applications using Angular,…
Cross-site request forgery is a vulnerability tracked by ThreatCluster, appearing in 13 threat clusters built from 14 intelligence report mentions.
The most recent intelligence report mentioning Cross-site request forgery on ThreatCluster is dated July 23, 2026. Activity was first observed October 28, 2025, giving a tracked span from then to July 23, 2026.
Across ThreatCluster reporting, Cross-site request forgery most frequently co-occurs with Brute Force, Credential Stuffing, Cross-site Scripting, Data Breach, Malware, among 12 tracked related entities.
The most significant recent cluster is “Cisco IOS Vulnerability CVE-2008-4128 Under Active Exploitation” (5 articles · Updated July 14, 2026). Cross-site request forgery appears across 13 threat clusters in total, listed above with sources.
Cross-site request forgery appears in 14 intelligence report mentions across 13 deduplicated threat clusters, aggregated from 17,000+ monitored sources.