Italian Bank XSS utilized by fraudsters

"An extremely convincing phishing attack is using a cross-site scripting vulnerability on an Italian Bank's own website to attempt to steal customers' bank account details. Fraudsters are currently sending phishing mails which use a specially-crafted URL to inject a modified login form onto the bank's login page. The vulnerable page is served...
Looking for something else or having a hard time finding a story? We recently moved things around so please use the search bar on the right!