Third-Party Scripts on Websites Present a 'Broad & Open' Attack Vector
Nearly half of the world's largest websites use externally generated JavaScript that makes them ripe targets for cyberattackers interested in stealing data, skimming credit cards, and executing other malicious actions.
United Kingdom Hadar Blutrich British Airways Source Defense Tempting Attack Vector Combat External Script
Source: darkreading.com