This webpage tries to include Brightspace.ru.nl inside a frame.

Your browser will probably allow this, as Brightspace apparently does not try to prevent this using X-Frame-Options or some CSP policy.

We can also make the iframe containing the Brightspace page transparent, as (not :-) shown below. Moving your mouse around on the blank space below you can tell there is some content there, because the cursor changes shape when you move over clickable invisible links and the link may be displayed. bottom of the browser. Look at the source code to see how this is done.

I can't really think of interesting attacks that use this. It might be possible to trick students into pressing some buttons on the hidden Brightspace page, e.g. to unenroll from the Web Security course, by displaying a fake button on top of it. But the layout of the Brightspace page differs per user so the positions of interesting buttons to click is hard to predict.