Glossary
Content Security Policy (CSP)
A browser security standard that lets a website specify, via an HTTP header, which sources of scripts, styles, and other content are allowed to load, significantly reducing the impact of cross-site scripting attacks even if an injection flaw exists. A strict CSP is one of the most effective single mitigations against XSS.
Recent coverage mentioning Content Security Policy (CSP)
Recorded Future Enhances Third-Party Risk with Unified Threat Intel
Recorded Future integrates threat intelligence and risk ratings into a unified third-party risk management platform to proactively identify vendor compromises.
Webmail CSS Injection: Hidden Data Exfiltration Threats
Security researchers warn that Cascading Style Sheets can exfiltrate sensitive data from webmail inboxes if vendors fail to sanitize styles.
Advertisement