Hackers exploited a flaw in Krpano to inject spam into more than 350 sites

A Cross-Site Scripting (XSS) vulnerability in a virtual tour framework has been exploited by malicious actors to inject scripts and manipulate search results, affecting more than 350 websites in a massive spam campaign called 360XSS.

jueves, 27 de febrero de 2025 • 1 min read • Q2BSTUDIO Team

Software-Company-Apps

A cross-site scripting (XSS) vulnerability in a virtual tour framework has been exploited by malicious actors to inject scripts into hundreds of websites, aiming to manipulate search results and execute a massive unwanted ad campaign.

According to security researcher Oleg Zaytsev, in a report shared with The Hacker News, the campaign dubbed 360XSS has affected more than 350 websites. This type of vulnerability allows attackers to insert malicious content into legitimate pages, compromising the security and integrity of the affected sites.

At Q2BSTUDIO, as a company specialized in development and technology services, we understand the importance of protecting digital platforms against such threats. Our team constantly works to offer secure and optimized solutions to prevent attacks like XSS, ensuring the integrity of websites and protecting users from cyber risks.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.