OK, this is eerie: vulnerabilities @ ING site
“We discovered CSRF vulnerabilities in ING’s site that allowed an attacker to open additional accounts on behalf of a user and transfer funds from a user’s account to the attacker’s account.”. I do not understand what’s this about, but it’s scaring me as hell. Via Jeff Atwood.