Showing only posts tagged cross-site scripting. Show all posts.

Spies hack high-value mail servers using an exploit from yesteryear

Source

Threat actors, likely supported by the Russian government, hacked multiple high-value mail servers around the world by exploiting XSS vulnerabilities, a class of bug that was among the most commonly exploited in decades past. XSS is short for cross-site scripting. Vulnerabilities result from programming errors found in webserver software …