CYBERSECURITYTRACKER
TRACKING7,415 stories in this site build1,561 vulnerability news stories in this site build
Permanent story citation

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4095

As cited

Copy frozen at (site build).

threat intel

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Researchers demonstrated new CSS-based attacks that allow malicious email content to break out of message boundaries and interfere with webmail interface elements across multiple providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. These techniques can capture credentials, hijack tokens, and manipulate legitimate user actions within the webmail application.

Why it matters: Email users at any organization relying on these webmail platforms face credential theft and account takeover through specially crafted emails; security teams should assess whether their email security tools catch such CSS manipulation and consider user awareness training about unusual email behavior.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Researchers demonstrated new CSS-based attacks that allow malicious email content to break out of message boundaries and interfere with webmail interface elements across multiple providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. These techniques can capture credentials, hijack tokens, and manipulate legitimate user actions within the webmail application.

Why it matters: Email users at any organization relying on these webmail platforms face credential theft and account takeover through specially crafted emails; security teams should assess whether their email security tools catch such CSS manipulation and consider user awareness training about unusual email behavior.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary