Ari Novick, a malware researcher at identity security specialist CyberArk, explained in a blog post that the XSS bug was ...