Software security researcher Justin Steven found an unfixed DOM XSS vulnerability in the Gartner Peer Insights widget that dates back to the original development of the software. Many websites were made vulnerable due to the bug, including Vodafone and LogRhythm. Gartner has since patched the flaw, following an initial failed fix attempt.

ISC Stormcast For Monday, October 20th, 2025 https://isc.sans.edu/podcastdetail/9662
ISC Stormcast For Monday, October 20th, 2025 (Sun, Oct 19th)