logo

CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Keyloggers

ID: 01f6817d-b44e-5602-b7c1-406290212bb2

STIX ID: report--01f6817d-b44e-5602-b7c1-406290212bb2

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-08-09

Date Updated: 2026-08-19

Author: Guru Baran

...
...

**CSS bomb** attacks leverage legitimate HTML/CSS features and sanitizer inconsistencies in major webmail clients to build real-time, JavaScript-free keyloggers and data exfiltration chains (demonstrated against Outlook, Gmail, Fastmail, ProtonMail, etc.), some of which have been patched while others reportedly remain unaddressed; recommended mitigations include sandboxed rendering, blocking risky selectors and disallowing auto-loading remote images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.