logo

Over 350 High-Profile Websites Hit by 360XSS Attack

ID: df8a812a-d357-592f-af28-422ac3ce69d0

STIX ID: report--df8a812a-d357-592f-af28-422ac3ce69d0

Feed Name: HackRead

Threat Score
70/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A widespread campaign named 360XSS exploited a default configuration reflected XSS flaw (CVE-2020-24901) in the Krpano virtual tour framework to inject XML-based payloads into URLs, hijack search results via SEO poisoning, and redirect visitors of over 350 high-profile sites (including government, university, and news domains) to spam advertisements; Krpano has released patches and organizations are advised to update and disable the vulnerable passQueryParameter setting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.