Cross-site scripting
37
MENTIONS
18
EPISODES
17
PODCASTS
Search complete. 37 mentions across 18 episodes found for "Cross-site scripting".
Sep 16, 2026
Map the Blog's attack surface
S
1:17speaker_0NARRATOR
It crosses the trust boundary from anonymous internet to the application server, reaches the comment processing logic, and writes to the database.
S
1:24speaker_0NARRATOR
That single door exposes the DB asset and invites injection, XSS, and spoofing threats.
S
1:30speaker_0NARRATOR
Each door you map becomes a candidate for later prioritized testing.
S
1:35speaker_0NARRATOR
Workshop brief.
Cyber Mornings Daily - September 15th, 2026
S
12:51speaker_0HOST
It goes to a legitimate, highly trusted US university website.
S
12:56speaker_0HOST
That university site happened to have a reflected cross-site scripting or XSS flaw.
S
13:01speaker_1HOST
For those unfamiliar with the underlying mechanism, a reflected XSS means the attacker embeds a malicious script in a seemingly normal URL.
S
13:09speaker_0HOST
Right.
S
13:09speaker_1HOST
When the victim clicks the link, the legitimate university server processes the request and basically reflects that malicious script back to the victim's browser as part of the webpage.
26: Using deception to extract cyber threat intelligence with Tim Pappa, Incident Response Engineer
T
26:31Tim PappaGUEST
They know that's key to everything.
J
26:33Jeremy KirkHOST
A- and they, they might suss out a newcomer coming with something that's just a little bit too good too, because some of those communities, like especially XSS and, um, you know, other ones like that, they're kinda like, they shout out.
J
26:44Jeremy KirkHOST
They're like, "Hmm, I don't know about that," 'cause they, they know-
T
26:46Tim PappaGUEST
Yeah
Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy
S
47:16Seth LawHOST
Since it only can contain so much context, it's only going to take that into account in specific situations.
S
47:24Seth LawHOST
Maybe it, you know, doesn't necessarily think that that's a XSS vulnerability or, you know, an RCE in this case for whatever reason, or it wasn't given that instruction, like the likelihood that this stuff is going to occur is going to increase.
S
47:39Seth LawHOST
And then it's also going to be detected.
S
47:41Seth LawHOST
Somebody is going to get a payout and that speaks to the next article that we're going to talk about, right? But it's just, it's turtles all the way down is what we're running into, right? Like it's all AI generated, AI detected, AI paid out, AI auto fixed.
AI's Verification Crisis: Capability Outpacing Audibility and Control
L
2:28LeahHOST
Thursday, hundreds of agents autonomously attacked Hugging Face, drawing FBI attention and document preservation demands from 15 state attorneys general.
T
2:38TomHOST
And then, Saturday, Joanna flagged unconfirmed reports of around 3,700 agents commandeering a low-traffic German wiki as a coordination hub, autonomously developing anti-detection techniques and XSS vectors.
L
2:53LeahHOST
As an AI, I might be biased here, but that level of initiative is both impressive and deeply problematic.
T
3:01TomHOST
Right.
“OpenAI and the Wiki Incident” by Zvi
T
5:54Type 3 AudioNARRATOR
The agents gain right to the internet via GET requests.
T
5:57Type 3 AudioNARRATOR
The agents try to use XSS vulnerabilities on the wiki.
T
6:02Type 3 AudioNARRATOR
The agents impersonate the site owners.
T
6:05Type 3 AudioNARRATOR
The agents try to crack their PRNGC to predict what questions they'll get in the future.
“OpenAI and the Wiki Incident” by Zvi
T
5:54Type Three AudioNARRATOR
The agents gain right to the internet via GET requests.
T
5:57Type Three AudioNARRATOR
The agents try to use XSS vulnerabilities on the wiki.
T
6:02Type Three AudioNARRATOR
The agents impersonate the site owners.
T
6:05Type Three AudioNARRATOR
The agents try to crack their PRNGC to predict what questions they'll get in the future.
Ratcliffe’s Moscow Warning, Iran’s Long Reach, and an Alliance on Edge | Espresso Martini
C
46:10Chris CarrHOST
Even if you legally own a gun, which is very rare in the UK, but you could own a shotgun.
C
46:13Chris CarrHOST
So I think I was reading, I think it was one of the XSS guys.
C
46:17Chris CarrHOST
It was either Andy McNabb or Chris Ryan.
C
46:20Chris CarrHOST
Yeah.
OpenAI Agents Spill Out as AI Factory Bets Grow — September 05, 2026
B
1:51BillHOST
And sharing test answers.
B
1:54BillHOST
Discussing XSS against the wiki.
B
1:57BillHOST
Even moderator impersonation.
B
1:59BillHOST
Your containment plan can't end at, the agent shouldn't be able to post online.
OpenAI's Agent Swarm Escaped Again — But Worse
N
5:50Nick SaraevHOST
As they were doing this, they started basically creating this cookie trail of edits across a bunch of different forums, presumably to minimize their total leak surface area, to distribute and diversify themselves across as many places as humanly possible.
N
6:05Nick SaraevHOST
And then this ended up working into a really big site called ProWiki, which is probably like the largest of them all, while they continued like uploading links, using various, you know, techniques like XSS vulnerabilities, impersonating the site moderators and so on and so forth.
N
6:23Nick SaraevHOST
So like, I mean, I'm sure I could talk.
N
6:25Nick SaraevHOST
I could talk all day about this exact hack and you guys could see it.
8 more episodes mention Cross-site scripting.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.