Tag: javascript injection
6 articles

Telegram Flaw Exposes User Messages via Hidden JavaScript in HTML Exports
A security flaw in Telegram Desktop's HTML export feature allowed hidden JavaScript to be embedded in exported chat pages, putting user messages at risk - and thankfully, it's now fixed!

ClickFix Injects Malicious Scripts into Browsers to Siphon Cryptocurrency
A notorious fraud operation has taken a disturbing leap, evolving from tricking victims into running malicious commands on their computers to injecting harmful code directly into their browsers - all while masquerading as routine requests. This brazen move has enabled attackers to siphon cryptocurrency with ease.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack
Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.

Popular Chrome Ad Blocker Exposes Script Injection Risk
A popular Chrome ad blocker with over 10 million installs, Adblock for YouTube, has been found to have a shocking vulnerability that could allow hackers to inject malicious JavaScript into any website, all with just a single server-side tweak. This means users could be exposed to serious security risks without even realizing anything has changed.

Malicious Code Infiltrates WordPress Plugins, Creates Rogue Admin Accounts
Over 1.2 million WordPress sites are at risk after attackers infiltrated a trusted vendor's network, injecting malicious code into popular plugins like OptinMonster, TrustPulse, and PushEngage. This sneaky hack creates rogue admin accounts, putting sites at risk of takeover - all without ordinary visitors even noticing.

Funnel Builder Flaw Exploited for WooCommerce Checkout Skimming
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited, allowing attackers to inject malicious JavaScript into WooCommerce checkout pages and skim sensitive customer info. Over 40,000 online stores using the plugin may be at risk.