Security News

Serious XSS vulnerability discovered in Signal
2018-05-16 10:37

Researchers have discovered a serious cross-site scripting (XSS) vulnerability affecting all desktop versions of Edward Snowden’s favourite security application, Signal.

Electron spins out a patch for bad XSS bug
2018-05-14 00:11

Attacker could skip past developer protections and get nasty Electron developers need to check their apps, after a security researcher turned up a remote code execution bug in the framework.…

Drupal Patches Critical Bug That Leaves Platform Open to XSS Attack
2018-02-23 22:13

Drupal has patched several vulnerabilities – both moderately critical and critical – in two versions of its content management system platform.

XSS, SQL Injection Flaws Patched in Joomla
2018-02-07 15:03

One SQL injection and three cross-site scripting (XSS) vulnerabilities have been patched with the release of Joomla 3.8.4 last week. The latest version of the open-source content management system...

Google Warns DoubleClick Customers of XSS Flaws
2017-12-21 19:44

Google has warned DoubleClick customers that some of the files provided by third-party vendors through its advertising platform can introduce cross-site scripting (XSS) vulnerabilities. read more

Firefox 57 to Get New XSS Protections
2017-10-06 16:06

Mozilla this week announced plans to boost the Cross-Site-Scripting (XSS) protections in Firefox by treating data URLs as unique origin. read more

Reflected XSS Bug Patched in Popular WooCommerce WordPress Plugin (Threatpost)
2017-08-31 13:30

Automattic has patched a reflected cross-site scripting vulnerability in the WooCommerce WordPress plugin.

IBM Patches Reflected XSS in Worklight, MobileFirst (Threatpost)
2017-08-02 19:11

IBM fixed a cross-site scripting vulnerability in its Worklight and MobileFirst products that could have let an attacker steal sensitive information.

Most SharePoint Installations Vulnerable to XSS Attacks (Security Week)
2017-06-15 10:43

One of the vulnerabilities patched by Microsoft this week with its monthly security updates is a potentially serious cross-site scripting (XSS) flaw believed to affect most SharePoint 2016...

Verizon Patches XSS Issues in its Messaging Client (Threatpost)
2017-05-22 19:25

Verizon patched late last year persistent- DOM-based cross-site scripting vulnerabilities in its Message+ messaging client that could allow an attacker to control a user's session.