Security news aggregator

Latest coverage for XSS

Stay informed on XSS vulnerabilities and defenses with the latest news, expert insights, and security tips on cross-site scripting threats.

92 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

XSS, or Cross-Site Scripting, is a type of vulnerability in web applications that allows attackers to inject malicious scripts into web pages viewed by other users. This security flaw enables attackers to bypass access controls, such as the same-origin policy, which are designed to segregate different websites from each other. XSS exploits the trust a user has for a particular site, allowing the attacker to send scripts that appear to be from the site itself.

In the context of information security, XSS is a significant concern as it can be used for various malicious activities, including stealing session tokens, login credentials, or personally identifiable information; defacing websites; or redirecting users to hostile sites. Protecting against XSS requires careful coding practices, such as sanitizing user input and using security measures like Content Security Policy (CSP). Identifying and mitigating XSS vulnerabilities is crucial for maintaining the integrity and security of web applications.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 92 Filtered view

On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. [...]

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, stating they have been actively exploited in the wild

PLUS: Firefox adds XSS protection; Leadership turnover at CISA; FTC exempts some data collection Infosec In Brief DNS vulnerabilities are being addressed 84 percent faster in the UK public sector thanks to an automated vulnerability scanning system established as part of a program kicked off early last year.…

Cybersecurity researchers have disclosed a cross-site scripting (XSS) vulnerability in the web-based control panel used by operators of the StealC information stealer, allowing them to gather crucial insights on one of the threat actors using the malware in their operations

Krebs on Security 9 months, 4 weeks ago

Who Got Arrested in the Raid on the XSS Crime Forum?

On July 22, 2025, the European police agency Europol said a long-running investigation led by the French Police resulted in the arrest of a 38-year-old administrator of XSS, a Russian-language cybercrime forum with more than 50,000 members. The action has triggered an ongoing frenzy of speculation and panic among XSS denizens about the identity of the unnamed suspect, but the consensus is that he is a pivotal figure in the crime forum scene who goes by the hacker handle "Toha." Here's a deep dive on what's knowable about Toha, and a short stab at who got nabbed.

React conquered XSS? Think again. That's the reality facing JavaScript developers in 2025, where attackers have quietly evolved their injection techniques to exploit everything from prototype pollution to AI-generated code, bypassing the very frameworks designed to keep applications secure

Also: Clorox Sues IT Vendor Over Password BlunderThis week, XSS forum admin arrested, Clorox sued Cognizant, Lumma Stealer is back, NY regulates water, U.S. maritime cybersecurity rules in effect, new Coyote banking Trojan, a hacker nabbed details of Mexico City auxiliary police, Latin America cyberattacks, and World Leaks stole synthetic data.

Also: Clorox Sues IT Vendor Over Password BlunderThis week, XSS forum admin arrested, Clorox sued Cognizant, Lumma Stealer is back, NY regulates water, U.S. maritime cybersecurity rules in effect, new Coyote banking Trojan, a hacker nabbed details of Mexico City auxiliary police, Latin America cyberattacks, and World Leaks stole synthetic data.

Loading more headlines...