“Serverless” Phishing Campaign
isc.sans.edu
isc.sans.edu
This is one reason why we (INKY) sanitize HTML to normalize character representations, remove JavaScript, XSS, etc. You can no longer rely on client-side sanitization as you could in the desktop client days (though even some of the better web services, like Fastmail actually do sanitize). It's also why you have to be super paranoid about HTML attachments now.