University researchers created a browser-based JavaScript that leverages a phone’s smart device sensor data to steal PINs.
Tag Archives: malicious JavaScript
Unpatched Vulnerability on Wix.com Puts Millions of Sites at Risk
Wix websites are vulnerable to reflective DOM cross-site scripting attack that could give attackers control of user’s websites.
Diary of a Ransomware Victim
A major online casino ran headfirst into a ransomware infection and learned about how simple mistakes can lead to complicated problems.
Adobe Patches DOM-XSS Flaw in Analytics AppMeasurement for Flash Library
Adobe today patched a DOM-based cross-site scripting vulnerability in the Adobe Analytics AppMeasurement for Flash library.
Critical Yahoo Mail Flaw Patched, $10K Bounty Paid
A researcher earned a $10,000 bounty from Yahoo for a stored cross-site scripting vulnerability in Yahoo Mail.
JavaScript DDoS Attack Peaks at 275,000 Requests-Per-Second
CloudFlare reports a massive JavaScript-based DDoS attack against one its customers, likely carried out by unsuspecting mobile browsers served a malicious ad.
WordPress Patches Zero-Day Vulnerability
WordPress quickly turned around a patch for a stored cross-site scripting zero-day vulnerability in the CMS’ core engine.
WordPress 4.0.1 Update Patches Critical XSS Vulnerability
The latest version of WordPress, 4.0.1, patches a critical cross-site scripting vulnerability in comment fields that enables admin-level control over a website.