• infeeeee@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    Isn’t “halfclick” a mousedown? You are hacked before release the button

    The messages use generic lures and do not require the targeted user to click on a link or open an attachment. The XSS exploit is embedded directly in the HTML body of the message and fires as soon as the victim opens or previews it in the vulnerable Zimbra webmail client. No further user interaction is required.