Blog Feeds Provide New Security Threat

LAS VEGAS — Exploiting the vulnerability of blog feeds, hackers have found a new medium to surreptitiously attack PCs.

Bob Auger, a security engineer with SPI Dynamics, said that hackers could insert malicious JavaScript in blog updates that are delivered to subscribers’ machines via Really Simple Syndication (RSS) or Atom feeds. Auger presented his findings during the annual Black Hat Briefings, an Internet security conference.

Auger said blog feeds can be compromised in two ways: hackers setting up a corrupted blog and getting users to subscribe to its RSS feed, or more likely, inserting malicious code into a popular blog’s comments section, which often have their own feed.

Attackers also can send malicious code to mailing lists that offer feeds to attack compromised systems, Auger said. Feeds have risen to prominence because they allow users to consolidate information from websites into a single interface. This eliminates the need for clicking on a plethora of different websites.

Many RSS or feed readers do not include security software that can filter out malicious code. Auger said these applications should prevent JavaScript from running.

“A large percentage of the readers I tested had some kind of an issue,” Auger said. Vulnerable feed readers include Bloglines, RSS Reader, RSS Owl, Feed Demon and Sharp Reader, according to Auger.

Filtering out JavaScript at the feed reader level can get complicated because many readers use the code to deliver ads like one would see if they accessed the blog homepage.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Judge Dismisses Last NCOSE-Backed Suit Over Kansas AV Law

A federal judge on Monday dismissed a lawsuit alleging that adult site SuperPorn violated Kansas’ age verification law, citing lack of jurisdiction after similarly dismissing two related cases earlier this year.

ASACP Rolls Out 'Restricted to Adults' Labeling Tool Updates

The Association of Sites Advocating Child Protection (ASACP) has updated its Restricted to Adults (RTA) labeling system.

Federal AV Proposal Scores Minor Win in House but Remains in Doubt

A newly announced bipartisan agreement in the U.S. House of Representatives Committee on Energy and Commerce may soon bring a proposed federal age verification law before the full House, but the measure continues to face an uphill battle.

Arizona Governor Vetoes 'Protect Act' With New Consent Provisions

Arizona Governor Kate Hobbs on Friday vetoed HB 2133, the “Protect Act,” which would have imposed new requirements for adult content uploaded online.

Brazil Begins Monitoring 18 Adult Sites for AV Compliance

Brazil’s National Data Protection Authority (ANPD) is now monitoring 18 high-traffic adult websites for compliance with the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires such sites to age-verify users located in Brazil.

Ofcom Fines First Time Videos $100,000 for AV Noncompliance

U.K. media regulator Ofcom on Thursday imposed a fine of 80,000 pounds (more than $100,000) against First Time Videos, which operates FTVGirls.com and FTVMilfs.com, for failing to implement age checks required for compliance with the Online Safety Act.

Curves Ahead: How BBW Creators are Turning Differentiation Into Competitive Advantage

For centuries, curves have been celebrated as a symbol of beauty, sensuality and power. From the soft opulence of Rubens paintings to the glamorous silhouettes of pinup icons, fuller figures have long occupied a place in art, fashion and fantasy.

Woodhull Freedom Foundation to Host Virtual 'Pride' Edition of 'Fact Checked' Series

Woodhull Freedom Foundation is hosting a Pride Month virtual edition of its series “Fact Checked by Woodhull.”

'InMelanin' Relaunches Through PAYSITE

InMelanin.com has officially relaunched through PAYSITE.

Pearl Industry Network Partners With Takedown Piracy

Industry trade group Pearl Industry Network (PiN) has officially partnered with Takedown Piracy.

Show More