Cross?
Why is this referred to as 'cross-site' scripting a lot, there's only one site involved?
Twitter said it identified and fixed the cross site scripting flaw that led to meltdown on Tuesday a month ago, only to undo this fix with a later web site update. The revamp - which reintroduced a flaw that meant JavaScript could be injected into Tweets - was unrelated to the recent introduction of New Twitter. The cross-site …
I noticed this morning that the pop-up profile box is missing from hovering @names in tweets, so I guess they just removed all JS stuff like for a little while until they sort it properly.
I think there were some malicious variants. Some definitely attempted to compile information via DMs
There was no signal to disrupt with the noise.
I'm sure there were some engineers on shift, but anyone with a high enough pay grade to actually make a decision about deploying a fix would be either snoozing or too busy trying to figure out how to actually make some money off of Twitter.