During normal browsing on YouTube, at some point, the antivirus Avast reported something that was not good.
From the Chrome Inspector it appears that one of the ads is infected and tries to load a crypto miner from Coinhive
Everything has been reported to Google, now I await the answer.
What is a XSS attack?
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.
If you use Thunderbird and plugins like Enigmail you have the option to import all PGP keys related to email addresses that are present in your address book.
First of all you need is to specify a key server, like pgp.mit.edu, then the plugin, for every single email address, will look for corresponding PGP key and will prompt you if you want to import results.
But, some times, the key is not what you’ll expect.
Some entries contains invalid data, and to be more specific, can contain malicious code.
Keep your eyes open, and avoid mass import of PGP keys.