Content Security Policy — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 5, 2025
Last Seen
December 5, 2025

Content Security Policy is a technology platform tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 5, 2025; most recent activity December 5, 2025.

Overview

Content Security Policy (CSP) is a web security standard that lets site operators define which sources and behaviors are allowed for a page, enforced via HTTP headers or meta tags. It mitigates risks like cross-site scripting (XSS), data exfiltration, and UI redress by restricting scripts, styles, images, and framing; effectiveness depends on thorough, correct configuration across the site. Misconfigurations or incomplete adoption can leave applications vulnerable, making CSP a key component of defense-in-depth for modern web apps.

Related Threat Clusters

  • New SVG Technique Enables Interactive Clickjacking Attacks

    A new technique utilizing SVG files has been identified, allowing attackers to create highly interactive clickjacking attacks. This vulnerability poses risks to users by enabling malicious actions through seemingly…

    4 articles · Updated December 5, 2025

Recent Intelligence Reports

  • Novel clickjacking attack relies on CSS and SVG — Theregister · December 5, 2025

CVSS v3.1 Breakdown