Fraudsters have taken advantage of a weakness in PayPal’s application to insert some XSS which ends up feeding your credit card number to their site. Surprisingly, it was first caught with Netcraft’s anti-phishing toolbar rather than some security experts. The full story is on Netcraft’s site.