Threat Intelligence Brief
Curated summary with source attribution
Source: ncl.ac.uk
Threat Risk: Medium
Victim: Newcastle University
Incident: Malicious XML injection in a virtual tour plugin leading to external redirects.
Impact: Users visiting the compromised link may be redirected to phishing or malware distribution sites.
Attacker: Unidentified threat actors
Analysis: Threat actors are exploiting the krpano virtual tour software by injecting a malicious XML payload into the URL parameters. By using the ‘include’ tag, attackers force the application to load content from a suspicious external domain, yapuza.xyz. This technique allows attackers to mask their activity behind the reputation of a trusted .ac.uk domain.
Recommendations: Update or remove legacy virtual tour plugins and outdated Flash-dependent software; Implement strict input validation and sanitization for all URL-based parameters; Deploy a robust Content Security Policy (CSP) to prevent the loading of unauthorized external resources
Source: URL Analysis
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source