Security News

JavaScript Library Introduced XSS Flaw in Google Search
2019-04-01 18:35

A change made several months ago in an open-source JavaScript library introduced a cross-site scripting (XSS) vulnerability in Google Search and likely other Google products. read more

WordPress 5.1.1 patches dangerous XSS vulnerability
2019-03-18 10:54

Researchers have offered more detail on a recently patched vulnerability that would allow an attacker to take over a WordPress site.

Don't be a WordPress RCE-hole and patch up this XSS vuln, pronto
2019-03-14 18:02

Not on 5.1.1? You should be A newly revealed vuln in the open-source CMS WordPress allows an unauthenticated website attacker to remotely execute code – potentially letting naughty folk delete or...

Researcher Earns $10,000 for Another XSS Flaw in Yahoo Mail
2019-02-22 07:14

A researcher says he has discovered yet another critical cross-site scripting (XSS) vulnerability in Yahoo Mail. The recently patched flaw could have been exploited to steal the targeted user’s...

Serious XSS flaw discovered in Evernote for Windows, update now!
2018-11-07 12:36

Online-note-sharing company Evernote has patched a hole that allowed attackers to infect notes shared via its service.

Recent Branch.io Patch Creates New XSS Flaw
2018-10-22 16:35

The patch for a recently disclosed cross-site scripting (XSS) vulnerability in Branch.io introduced another similar flaw, a security researcher revealed last week. read more

Branch.io Flaws Exposed Tinder, Shopify, Yelp Users to XSS Attacks
2018-10-15 05:13

Hundreds of millions of users may have been exposed to cross-site scripting (XSS) attacks due to a vulnerability present in Branch.io, a service used by Tinder, Shopify, Yelp and many others. read more

D-Link Patches Code Execution, XSS Flaws in Management Tool
2018-10-05 10:26

D-Link has released patches for several remote code execution and cross-site scripting (XSS) vulnerabilities found by researchers in the company's Central WiFiManager access point management tool....

Once Popular Online Ad Format Opens Top Tier Sites to XSS Attacks
2018-09-25 19:55

Online ad industry moves away from once prolific ads that are now deemed insecure because of DOM-based XSS vulnerabilities.

Sealed with an XSS: Lloyds Group should avoid cross talk, say IT pros
2018-09-20 13:50

We're secure, says bank A pair of IT workers have criticised banks within the Lloyds Banking Group (LBG) for sub-standard security. The group denies anything is amiss, maintaining it follows...