Comment on Microsoft doing shady Microsoft stuff again

<- View Parent
incompetent@programming.dev ⁨1⁩ ⁨day⁩ ago

It’s called a Drive-by Compromise:

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Browser push notifications may also be abused by adversaries and leveraged for malicious code injection via User Execution. By clicking “allow” on browser push notifications, users may be granting a website permission to run JavaScript code on their browser.

It’s not Hollywood fantasy, as you claim. It is a well documented attack vector.

source
Sort:hotnewtop