On MondayIE8 RC1 was released. Here are some of the most interesting improvements and bug fixes to the XSS Filter feature:
Some byte sequences enabled the filter to be bypassed, depending on system locale
URLs containing certain byte sequences bypassed the Beta 2 filter implementation in some locales. For example, with a Chinese locale system, URLs of the following format would bypass the filter: