logo

How has use of framing protection security headers changed in the past 3 years?, (Wed, Jun 10th)

ID: 6189b176-2c98-5098-80f8-5714a4293823

STIX ID: report--6189b176-2c98-5098-80f8-5714a4293823

Feed Name: SANS ISC Diary

Date Published: 2026-06-10

Date Updated: 2026-06-10

...
...

This diary analyzes HTTPS responses for the Tranco top 1M domains to measure adoption of X-Frame-Options and CSP frame-ancestors headers, comparing 2023 and 2026 data. It finds overall increased deployment—especially of CSP frame-ancestors—while noting gaps remain (many popular sites still lack framing protection), explains the methodology and directive breakdowns (SAMEORIGIN, DENY, 'self', 'none'), and highlights the security importance for mitigating iframe-based/phishing attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.