New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
Fastmail fixed two CSS mutation bugs and an image-proxy bypass, but CSS hotwiring and other techniques remain a concern for webmail security.
A Proton Mail vector demonstrated that a proxy bypass could expose the recipient's IP address, contradicting Proton's tracker-protection claims.
A paste race in Yahoo Mail and AOL Mail on Firefox can leak Medium email-login tokens, allowing account takeover.
CSS pseudo-elements and opacity can hide instructions from humans while AI models like OpenAI's Atlas read them, leading to data exfiltration. Atlas…
PortSwigger researcher Gareth Heyes presented new CSS-based attacks at Black Hat USA 2026 that can break webmail defenses to steal passwords and…
At Black Hat USA 2026, PortSwigger researcher Gareth Heyes presented new CSS attacks that break webmail defenses to steal passwords and tokens.
An attack chain in Outlook and Firefox spoofs a Microsoft sign-in screen and captures passwords by abusing allowed label elements and CSS…
Gmail's image-set() fallback can be abused to make external requests, enabling exfiltration of Slack tokens through prompt injection in AI-connected email workflows.