threat-intel
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
High
Summary
Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weaknesses in how webmail clients process HTML and CSS, enabling attackers to bypass security measures and inject malicious code. Several webmail providers have addressed some of these issues, but significant risks remain.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
