Over the past couple of years, cybercriminals have increasingly focused
on finding ways to inject malicious code into legitimate websites.
Typically they've done this by embedding code in an editable part of a
page and using this code to serve up harmful content from another part
of the Web. But this activity can be difficult to spot because websites
also increasingly pull in legitimate content, such as ads, videos, or
snippets of code, from outside sites.