MEDIUMVulnerability
Global

Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu

·Source: The Hacker News

Updated:

Executive Summary

A bank approved a Taboola pixel. That pixel quietly redirected logged-in users to a Temu tracking endpoint. This occurred without the bank’s knowledge, without user consent, and without a single security control registering a violation. Read the full technical breakdown in the Security Intelligence Brief. Download now → The "First-Hop Bias" Blind Spot Most&

Analysis

A bank approved a Taboola pixel. That pixel quietly redirected logged-in users to a Temu tracking endpoint. This occurred without the bank’s knowledge, without user consent, and without a single security control registering a violation. Read the full technical breakdown in the Security Intelligence Brief. Download now → The "First-Hop Bias" Blind Spot Most&
Source Attribution

Originally published by The Hacker News on Apr 16, 2026.

Related Threats