Meet clickjacking's slicker cousin, gesture jacking

Despite continuing efforts to mitigate the risk through bug fixes and browser behavior changes, intrusive attack variations continue to emerge...
The latest variation of the technique has been dubbed 'cross window forgery,' by Paulos Yibelo, a security analyst at Amazon...
...this can lead to an account takeover if a victim that is logged into either site goes to an attacker website and holds the Enter/Space key...
Read at Theregister