Slow Mist Yuxian posted on X: "Another XSS attack targeting the Crypto industry. The attacker exploited the XSS vulnerability of the Cointelegraph website to trick the target user into opening the Cointelegraph official website link (with XSS malicious script, Figure 1 address bar), so: <span style="display: inline !important;"></span>
<span style="display: inline !important;">-The malicious script is loaded and executed; </span>
<span style="display: inline !important;">-The address bar is set to https://cointelegraph[.]com/not-public/drafts/article-1033, and it was thought to be an official unpublished draft; </span>
<span style="display: inline !important;">-Then a fake Sign in with X box pops up; </span>
<span style="display: inline !important;">-Click Sign in with X Then open the third-party application authorization of X, and there is a huge blank space in the permission list, which is very sneaky... If you don't notice and click on the authorization, your X-related permissions will be taken over by the attacker. </span>
<span style="display:inline !important;">-The rest is up to you. This kind of phishing with a little vulnerability exploitation is even more difficult for the general public to defend against, so pay attention. ”</span>