I’m getting code injected into posts on one of my blogs as well, and I just upgraded to 2.3.3 to try and prevent this and it happened again
Same as Fluxinul:
<font style=”position: absolute;overflow: hidden;height: 0;width: 0″><!–4848–><a href=”
100s of spam links
</font>
How do I lock this down?