<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Anti Targeted Attack Platform — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/anti-targeted-attack-platform/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 27 May 2026 14:31:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/anti-targeted-attack-platform/feed.xml" rel="self" type="application/rss+xml"/><item><title>Kaspersky Anti Targeted Attack Platform Multiple XSS Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-05-kaspersky-ata-xss/</link><pubDate>Wed, 27 May 2026 14:31:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-kaspersky-ata-xss/</guid><description>Multiple vulnerabilities have been discovered in Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7, allowing an attacker to cause a remote cross-site scripting (XSS) vulnerability, tracked as CVE-2026-28348 and CVE-2026-28350.</description><content:encoded><![CDATA[<p>Multiple vulnerabilities have been discovered in Kaspersky Anti Targeted Attack Platform. These vulnerabilities, tracked as CVE-2026-28348 and CVE-2026-28350, can be exploited to perform a remote cross-site scripting (XSS) attack. This impacts versions of Kaspersky Anti Targeted Attack Platform prior to 7.1.7. Exploitation of these vulnerabilities allows an attacker to inject malicious scripts into the web pages viewed by other users. A successful XSS attack can lead to session hijacking, defacement of websites, or redirection of users to malicious sites.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies a vulnerable endpoint within the Kaspersky Anti Targeted Attack Platform web application. This endpoint accepts user-controlled input without proper sanitization.</li>
<li>The attacker crafts a malicious URL or injects malicious code into a form field that will be processed by the vulnerable endpoint. This malicious code includes JavaScript or other client-side scripting languages.</li>
<li>The attacker delivers the crafted URL to a victim user, typically through phishing, social engineering, or by injecting the link into another part of the application.</li>
<li>The victim user clicks on the malicious link or interacts with the injected form.</li>
<li>The vulnerable endpoint processes the attacker-supplied input and embeds it into the HTML response without proper encoding or sanitization.</li>
<li>The victim&rsquo;s web browser renders the HTML response, executing the attacker&rsquo;s injected script.</li>
<li>The injected script executes within the security context of the victim&rsquo;s browser, allowing the attacker to access cookies, session tokens, and other sensitive information.</li>
<li>The attacker uses the stolen information to hijack the victim&rsquo;s session, deface the web application, or redirect the victim to a malicious website.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these XSS vulnerabilities (CVE-2026-28348, CVE-2026-28350) in Kaspersky Anti Targeted Attack Platform can lead to unauthorized access to sensitive data, including user credentials and internal system information. The impact ranges from defacement to complete account takeover. Since the vulnerability exists in a security product, successful exploitation severely undermines the security posture of affected organizations. The number of potential victims depends on the user base of the affected Kaspersky Anti Targeted Attack Platform installations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Kaspersky Anti Targeted Attack Platform to version 7.1.7 or later to remediate CVE-2026-28348 and CVE-2026-28350 (see Kaspersky Security Bulletin 12430#260526).</li>
<li>Implement a Web Application Firewall (WAF) with rules to detect and block common XSS attack patterns targeting the Kaspersky Anti Targeted Attack Platform web interface.</li>
<li>If upgrading is not immediately feasible, consider implementing input validation and output encoding on the Kaspersky Anti Targeted Attack Platform web interface as a temporary mitigation.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>xss</category><category>vulnerability</category><category>web-application</category></item></channel></rss>