XSS in Tweetdeck (don't view in Tweetdeck...)
twitter.com
twitter.com
For some reason this is hilarious to me. Not the pinnacle of responsible disclosure, but no real harm done.
<script>javascript</script> is the first payload you try when looking for the stupidest XSS you can find....
I'm not saying that's what happened here, and depending on the language and platform you're using, xss can be a difficult problem to solve. But it does seem to be a common trait to disregard security until you have to apologize for it.
[1] http://www.theguardian.com/technology/2014/jun/11/twitter-tw...
http://thenextweb.com/twitter/2014/06/11/tweetdeck-users-xss...