Page 1 of 1

The Exploiters took advantage of a Krpano Framework flaw to inject spam ads on 350+ websites.

Posted: Fri Feb 28, 2025 3:27 pm
by Shane1145
A cross-site scripting (XSS) vulnerability in a virtual tour framework has been weaponized by malicious actors to inject malicious scripts across hundreds of websites with the goal of manipulating search results and fueling a spam ads campaign at scale.

Security researcher Oleg Zaytsev, in a report shared with The Hacker News, said the campaign – dubbed 360XSS – affected over 350 websites, including government portals, U.S. state government sites, American universities, major hotel chains, news outlets, car dealerships, and several Fortune 500 companies.

https://thehackernews.com/2025/02/hacke ... -flaw.html