CSS: The Hidden Threat Lurking in Your Inbox
ID: ac270369-43df-5686-bd64-9808d51c34a8
STIX ID: report--ac270369-43df-5686-bd64-9808d51c34a8
Feed Name: Dark Reading
Threat Score
Black Hat USA 2026 coverage: Research by Gareth Heyes demonstrates that CSS and HTML alone can be abused to construct keyloggers and data-exfiltration techniques in webmail, potentially bypassing protections that focus only on scripts or attachments; Heyes found flaws in major vendors, recommends stricter CSS sanitization, message isolation, and image proxying, and highlights inconsistent vendor handling of disclosures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
