#clickjacking
Developer attempts to replicate "Liquid Glass" in CSS, and once finished realizes what she'd actually created is an exploit for a fundamental, previously unknown, and rather serious browser vulnerability

lyra.horse/blog/2025/12...

"CSS hack accidentally becomes regular hack"
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
lyra.horse
December 5, 2025 at 2:03 AM
OOOH IM CLICKJACKING IM CLICKJACKING IT
February 11, 2026 at 7:39 PM
How to Make a Clickjacking Vulnerability Scanner with Python
How to Make a Clickjacking Vulnerability Scanner with Python
Learn how to create a Python script to detect clickjacking vulnerabilities in websites.
infosecwriteups.com
December 7, 2024 at 8:47 AM
yay! my first firefox cve!!

this bug is actually pretty fun, can't wait to be able to share the details
January 13, 2026 at 8:24 PM
my new blogpost is out!!

this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration

and i've already used it to get a google docs bounty ^^

have fun <3

lyra.horse/blog/2025/12...
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
lyra.horse
December 4, 2025 at 2:03 PM
giving a talk this valentine's day at disobey!

it's my bsides talk, except with more new svg clickjacking stuff!
February 10, 2026 at 6:48 PM
Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card details.
Major password managers can leak logins in clickjacking attacks
Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card details.
www.bleepingcomputer.com
August 20, 2025 at 2:50 PM
À la découverte du "SVG clickjacking"

"I’ve discovered a new technique that turns classic clickjacking on its head and enables the creation of complex interactive clickjacking attacks, as well as multiple forms of data exfiltration."

👉 lyra.horse/blog/2025...
December 9, 2025 at 8:42 PM
i've been dealing with a lot of mental health stuff recently and thus i've also been having trouble finishing the svg clickjacking blogpost

it'll come out but idk when, hopefully this month though, thank you for the patience <3
November 1, 2025 at 12:07 AM
New Podcast Episode:
Security Now: Clickjacking "Whac-A-Mole"
Inside the Password Manager Clickjacking Frenzy and What It Means
with Steve Gibson, @leolaporte.me
Clickjacking "Whac-A-Mole" | TWiT.TV
Alarm bells are ringing over a supposed browser zero-day, but is the threat as bad as it sounds? Steve reveals why “clickjacking” might be more whac-a-mole than breaking news
twit.tv
August 27, 2025 at 3:05 AM
i clicked a weird one that I'm 90% sure immediately did some sort of clickjacking on Indeed
May 8, 2026 at 5:23 PM
Caught a clickjacking vuln this week. Two missing headers, fixed fast.

Attack: invisible iframe + fake UI = users clicking your app without knowing.

Fix: X-Frame-Options: DENY + CSP frame-ancestors 'none'. Check your framework.

#SoftwareEngineering #BuildInPublic
May 11, 2026 at 1:05 PM
J’avais alerté en 2018 sur le danger de l’autofill. On m’avait dit « nan mais lol ». J’en ai marre d’avoir raison et qu’on m’écoute jamais…
www.bleepingcomputer.com/news/securit...
Major password managers can leak logins in clickjacking attacks
Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card ...
www.bleepingcomputer.com
August 22, 2025 at 10:06 AM
Browser-basierte Passwort-Manager? Allein der Gedanke daran löst bei mir unkontrolliertes Augenlider-Zucken aus.
Major password managers can leak logins in clickjacking attacks
Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card ...
www.bleepingcomputer.com
August 20, 2025 at 4:42 PM
Novel clickjacking attack relies on CSS and SVG
Novel clickjacking attack relies on CSS and SVG
Who needs JavaScript? Security researcher Lyra Rebane has devised a novel clickjacking attack that relies on Scalable Vector Graphics (SVG) and Cascading Style Sheets (CSS).…
dlvr.it
December 5, 2025 at 10:00 PM
O Lord, shield our domains from clickjacking, cross-origin deception, and unsanctioned embedding, that by Thy divine providence no malicious iframe may prevail against our Content-Security-Policy, and deliver us from all X-Frame-Options misconfiguration, through Christ our Lord, Amen.
also, they have a web interface that's a chatGPT clone, but with a section called "Holy Widgets"
April 10, 2026 at 1:51 PM
CVSS gave a clickjacking vulnerability a 9.6. CVSS said that a clickjacking vulnerability was the D-Plan "Emergency & I" of vulnerabilities. And nobody will ever hold them to account for it. Nobody will write a "reviews we got wrong" for CVSS scores 10 years later.
November 27, 2024 at 1:19 AM
Double-Clickjacking, or "press buttons on other sites without preconditions". After seeing and experimenting with this technique for a while, I cooked up a variation that combines many small tricks and ends up being quite convincing.
Here's a flexible PoC:
jorianwoltjer.com/blog/p/hacki...
The Ultimate Double-Clickjacking PoC | Jorian Woltjer
Combing a lot of browser tricks to create a realistic Proof of Concept for the Double-Clickjacking attack. Moving a real popunder with your mouse cursor and triggering it right as you're trying to bea...
jorianwoltjer.com
May 25, 2025 at 5:30 PM
Io uso KeePass.
Portable, offline, multipiattaforma, copi il DB (criptato) dove ti serve e sei a posto.

Alcune piattaforme hanno già rilasciato il fix e altre lo faranno nei prossimi giorni.
L'elenco è nell'articolo.

@signorina37.ransomnews.online

www.punto-informatico.it/password-man...
Password manager vulnerabili al clickjacking
I password manager più noti sono vulnerabili ad un attacco di clickjacking che permette di rubare password e dati delle carte di credito dal browser.
www.punto-informatico.it
August 24, 2025 at 9:16 AM
Clickjacking

What is it?

In clickjacking, the attacker tricks a user into clicking on something different than what the user perceives.
5/18
October 6, 2023 at 10:54 PM
Novel clickjacking attack relies on CSS and SVG www.theregister.com/2025/12/05/c...
Novel clickjacking attack relies on CSS and SVG
: Who needs JavaScript?
www.theregister.com
December 6, 2025 at 4:12 PM
Passwordstate, used by 29,000 orgs worldwide, just patched a critical flaw.

A crafted URL could bypass its emergency access page — exposing credentials.

Researchers also warn its browser extension was at risk of clickjacking: one bad click could leak logins, cards, even 2FA codes. #CyberAlerts
Click Studios Patches Passwordstate Authentication Bypass Vulnerability in Emergency Access Page
Passwordstate 9.9 fixes authentication bypass flaw on August 28, 2025, adding clickjacking defenses for 29,000 customers.
thehackernews.com
August 29, 2025 at 9:47 PM
🛡️ Security Now 1040:
🐧 Linux desktop malware appears
🍏 Apple patches a critical vulnerability
🐳 Docker escape flaw fixed

🎧 buff.ly/OZq5E9F

#CyberSecurity #InfoSec
Clickjacking "Whac-A-Mole" | TWiT.TV
Alarm bells are ringing over a supposed browser zero-day, but is the threat as bad as it sounds? Steve reveals why “clickjacking” might be more whac-a-mole than breaking news
buff.ly
August 28, 2025 at 11:00 PM
pic 2 shows an illustration of an attack where no part of it makes any sense, but seems to be a mix of traditional clickjacking + xss through an svg file - not at all what my research (or even the article) is about.
July 4, 2026 at 5:04 PM