This blog was originally published by Ryan Chaplin on the Raxis blog February 10, 2026 During several penetration tests last year, I observed clients often set unsafe directives for Google Tag Manager usually to supplement data collection via Google Analytics and third-party vendors. Aside from ...
Source: [Dev.to](https://dev.to/raxis/bypassing-a-waf-and-a-csp-with-google-tag-manager-an-attackers-perspective-and-remediation-advice-2pig)