Late last week, a security flaw in Internet Explorer 8 was publicly disclosed to the Full Disclosure mailing list. The flaw allows attackers to steal private information from online services such as web mail and Twitter, allowing attackers to, for example, delete e-mails or send tweets from their victims’ accounts.
The post was made by Google employee Chris Evans. He stated that the reason for going public was to try to persuade Microsoft to fix the problem—the new flaw is a variant on an older attack, and the details of the flaw were made public in a paper authored by Carnegie Mellon students that Evans reviewed. While the other major browser vendors have made fixes to their browsers to prevent attack—Chrome 4.0.249.78, Safari 4.0.5, and most recently Firefox 3.6.7 and 3.5.11 all include protection against the flaw—Microsoft has thus far failed to update Internet Explorer to provide protection.
Read the comments on this post

Read more from the original source:
Microsoft investigates public IE CSS XSS flaw; Twitter, Hotmail vulnerable



The Protomen - Rock Music and Mega Man Combined.
An Irrelevant Take on the Zombie Goodness of the Walking Dead
Halloween Fear Fest - Mega Shark VS Giant Octopus
Amnesia: The Dark Descent will induce heart problems.
Redline - 7 Years in the making and damn, it looks good.
Cool-O-Rama » Microsoft investigates public IE CSS XSS flaw ……
I found your entry interesting do I’ve added a Trackback to it on my weblog
…