Back to blog

Segui e iscriviti

Matthew Mathur

Matthew Mathur

Ricercatore senior in materia di sicurezza, Fastly

Matthew è un ricercatore senior di Fastly in materia di sicurezza e si concentra sulla ricerca di vulnerabilità, sugli attacchi alle applicazioni web e sullo sviluppo di protezioni. Matthew collabora attivamente a diversi strumenti di sicurezza open source, tra cui Metasploit Framework e Nuclei, e condivide con entusiasmo la propria ricerca con la community della sicurezza.
What is Style Smuggler (CVE-2026-75650)?Matthew Mathur, Team di ricerca sulla sicurezza di Fastly
CVE-2026-75650 (StyleSmuggler) is a critical SSTI being actively exploited in ecommerce platforms. Learn what it is and how Fastly customers can stay protected.
Sicurezza
An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
Che cos'è CVE-2026-66066? Proteggere l'app Rails dall'RCE in Active StorageMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
Scopri di più su CVE-2026-66066: una vulnerabilità di lettura arbitraria di file in Active Storage di Rails. Comprendi i rischi e proteggi il tuo ambiente con la nostra patch virtuale.
Sicurezza
Che cos'è CVE-2026-23869? Un allarme di sicurezza di React Server ComponentsMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
CVE-2026-23869: vulnerabilità ad alta gravità Denial of service nei React Server Components. Scopri gli impatti, le versioni interessate e ottieni protezione immediata con una patch virtuale.
SicurezzaApprofondimenti del settore
AI Bots in Q2 2025: Trends from Fastly's Threat Insights ReportMatthew Mathur, David King, +1
Fastly's Q2 2025 Threat Insights Report uncovers how Meta, OpenAI, and others are shaping web traffic and what organizations need to do to stay in control.
SicurezzaApprofondimenti del settore+1
ToolShell Remote Code Execution in Microsoft SharePoint: CVE-2025-53770 & CVE-2025-53771Simran Khalsa, Matthew Mathur, +1
Microsoft revealed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, actively exploited to compromise SharePoint servers.
Sicurezza
TLS configuration icon
OS Command Injection ExplainedMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
In this blog, we'll explore the web application vulnerability, OS Command Injection, and how to prevent it.
Sicurezza
CVE-2025-29927: Authorization Bypass in Next.jsMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
A critical Next.js Vulnerability (CVE-2025-29927) lets attackers bypass authorization. Protect your applications now.
Sicurezza
Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress PluginsTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa, +2
We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000.
SicurezzaApprofondimenti del settore
CVE-2023-30534: Insecure Deserialization in Cacti prior to 1.2.25Team di ricerca sulla sicurezza di Fastly, Matthew Mathur
We have discovered two instances of insecure deserialization in Cacti versions prior to 1.2.25, tracked as CVE-2023-30534.
Sicurezza
Back to Basics: Directory TraversalTeam di ricerca sulla sicurezza di Fastly, Matthew Mathur
In this post, we'll explore the application vulnerability directory traversal. What is it and how can you protect your apps from it?
Sicurezza
Network Effect Threat Report: Uncovering the power of collective threat intelligenceTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa, +3
Announcing the Network Effect Threat Report, Fastly’s threat intelligence report with insights based on unique data from April to June of 2023
SicurezzaApprofondimenti del settore+1
CVE-2023-34362: Progress MOVEit Transfer SQL Injection VulnerabilityTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa, +3
What you need to know about CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability
Sicurezza
Command Injection CVE-2021-25296: A Deep DiveTeam di ricerca sulla sicurezza di Fastly, Matthew Mathur
NagiosXI versions 5.5.6 to 5.7.5 are vulnerable to three different instances of command injection.
SicurezzaApprofondimenti del settore