Malicious actors have used a virtual tour framework’s cross-site scripting (XSS) vulnerability as a weapon to insert malicious scripts on hundreds of websites in an attempt to skew search results and support a large-scale spam ad campaign.
The campaign, known as 360XSS, impacted more than 350 websites, including government portals, U.S. state government websites, American universities, major hotel chains, news outlets, auto dealerships, and several Fortune 500 companies, according to a report by security researcher Oleg Zaytsev that was shared with The Hacker News.
The researcher said that this was more than just a spam campaign. The misuse of trusted domains was widespread read more about Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
