New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
Cybersecurity researchers at Zenity Labs have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents, codenamed AgentForger, that could allow a single…
Researchers at Manifold Security have disclosed two vulnerabilities in the Claude for Chrome browser extension that could allow rogue extensions to trigger…
A new malware strain named Umbrij, attributed to the advanced persistent threat (APT) group ToddyCat, is abusing OAuth 2.0 tokens to gain…
Gmail's image-set() fallback can be abused to make external requests, enabling exfiltration of Slack tokens through prompt injection in AI-connected email workflows.
Two security teams have demonstrated that OpenClaw, a popular self-hosted AI agent, can be tricked into executing attacker-controlled code or leaking sensitive…