BiDi Swap: The bidirectional text trick that makes fake URLs look real www.bleepingcomputer.com/news/secu…

Varonis Threat Labs is shining a spotlight on a decade-old vulnerability that opens the door to URL spoofing.

By exploiting how browsers handle Right-to-Left (RTL) and Left-to-Right (LTR) scripts, attackers can craft URLs that appear trustworthy but actually lead somewhere else, therefore this method, known as BiDi Swap, can be often abused in phishing attacks.

Edward Kiledjian @ekiledjian