Stepping Through A Mass Web Attack
ID: b2551bce-dd4b-5f83-bde5-2ee98e60b193
STIX ID: report--b2551bce-dd4b-5f83-bde5-2ee98e60b193
Feed Name: Zscaler Security Research Blog
**Mass web-based drive-by attack leveraging SQL injection and browser exploits** — The report describes attackers injecting code via SQL injection into vulnerable Microsoft ASP sites (including a noted compromise of Travelocity) to host scripts that chain multiple browser vulnerabilities, enabling large-scale client-side infections aimed at stealing credentials and delivering malware; mitigation recommendations include patch management, AV, and blocking malicious URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
