5 ms·
How is this supposed to be zero-click? All attack scenarios require either the attacker to modify configuration files, or the user to click on a malicious short
by jcarrano 3mo ago
How is this supposed to be zero-click? All attack scenarios require either the attacker to modify configuration files, or the user to click on a malicious shortcut.
- nikanj 3mo agoNo interactio needed from the user, presuming the attacker can already modify files and execute commands!
- Aachen 3mo ago> either the attacker to modify configuration files, or the user to click on a malicious shortcut. don't you mean "x and y" instead of "either x or y"? It's not triggered by a default-configured shortcut, you need both modifying of the shortcuts definition file and the target user to trigger it. Notably, modifying the shortcuts definition file requires a permission level equal to or higher than the user has