XSS
A krpano XSS redirect campaign, caught in CSP reports
A domain we'd never seen before, sb1es.com, popped up in our CSP threat-intel feed recently. It was flagged as a code/exfil hit against a customer site, and it looked like it might be a Magecart skimmer at first glance, so I started investigating. It turns