A cross-site scripting (XSS) vulnerability in the Krpano framework has been exploited to inject malicious scripts into over 350 websites, manipulating search results and spreading spam. Discovered by researcher Oleg Zaytsev, the flaw involved improper handling of the “xml” parameter. Krpano has since released an updated version to address this issue, urging users to update and secure their configurations.

Cyber attackers use images & built-in tools to bypass defences – SecurityBrief Australia
Cyber attackers use images & built-in tools to bypass defences SecurityBrief Australia