logo

Stepping Through A Mass Web Attack

ID: b2551bce-dd4b-5f83-bde5-2ee98e60b193

STIX ID: report--b2551bce-dd4b-5f83-bde5-2ee98e60b193

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Mass web-based drive-by attack leveraging SQL injection and browser exploits** — The report describes attackers injecting code via SQL injection into vulnerable Microsoft ASP sites (including a noted compromise of Travelocity) to host scripts that chain multiple browser vulnerabilities, enabling large-scale client-side infections aimed at stealing credentials and delivering malware; mitigation recommendations include patch management, AV, and blocking malicious URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.