The record
Written from the 1 report below. Nothing here is unsourced.
- Attackers are re-registering expired domain names that were once used by content delivery networks, allowing them to control content served to websites that still have hard-coded references to the old domain.
- Because these links reside in third-party scripts loaded by users' browsers, traditional server-side security tools often fail to detect the malicious activity.
- Organizations are increasingly using Content Security Policy in report-only mode to gain visibility into the scripts actually executing in their customers' browsers and to meet new compliance mandates.
What to watch next
- Growth in adoption of Content Security Policy as a standard for client-side visibility
- Increasing regulatory pressure from standards like PCI DSS v4.0.1
- Continued discovery of ClickFix and similar social-engineering campaigns via browser-side reporting
Coverage1
1 report
English national1
All filed from India
Named India · PCI DSS · Report URI
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
