Hack through LJ embedding

LJ has been used as the vector for a cross-site scripting attack through embedded media. The hack was only effective for two hours, and there's no danger of computers being infected through this.

Read all about it here, and see if you were affected.

Why this matters: if you use a hotmail or other free webmail account as your LJ mail account, and the mail-account has been cleaned up because of inactivity, a smart attacker could re-enable the account and take control of your Journal through the 'mail me my new password'-functionality.
Otherwise, the worst that could happen is an increase in spam.
