[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxn0vIkTjM1iZK9ExS-KUkIt3mRv3GNGkK5ERMebIcUo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"6dea4f03-58da-4c41-b7e7-0f7a6865ac42","css-based-attacks-bypass-webmail-defenses-to-steal-credentials-and-tokens","cc5e7e22-bd9d-41d6-8d8e-72d41bd782ee","CSS-Based Attacks Bypass Webmail Defenses to Steal Credentials and Tokens","Researchers revealed that attackers can exploit how email clients render HTML and CSS to interact with the surrounding webmail interface, enabling theft of passwords, session tokens, and hijacking of user actions. The root cause lies in insufficient sanitization and isolation of CSS within rendered email content — a configuration management failure where email clients do not adequately sandbox malicious styling rules. This matters because webmail is a high-value target: compromised session tokens grant full account access without needing credentials. While some providers like Fastmail and Proton Mail have issued patches, many clients remain under investigation, meaning users and organizations are currently exposed. The attack is particularly insidious because it requires no user interaction beyond opening a malicious email.","**Immediate actions:**\n- Apply vendor-issued patches for affected webmail platforms (e.g., Fastmail, Proton Mail) immediately upon release.\n- Disable or restrict HTML email rendering in high-security environments where plaintext email is a viable alternative.\n- Audit current email client configurations to enforce strict CSS and HTML sanitization policies.\n\n**Long-term improvements:**\n- Implement Content Security Policy (CSP) headers on webmail platforms to restrict unauthorized resource interactions.\n- Enforce email gateway filtering rules that strip or neutralize potentially malicious CSS and HTML constructs before delivery.\n- Adopt zero-trust principles for webmail sessions, including short-lived session tokens and re-authentication for sensitive actions.\n\n**Detection measures:**\n- Monitor webmail application logs for anomalous data exfiltration patterns, such as unexpected outbound requests triggered from email rendering.\n- Subscribe to vendor security advisories and threat intelligence feeds covering webmail and email client vulnerabilities.\n- Conduct regular penetration testing of webmail infrastructure to identify CSS\u002FHTML injection attack surfaces.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 7 – Continuous Vulnerability Management","CIS Control 9 – Email and Web Browser Protections","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SC-18 – Mobile Code","NIST SP 800-53 CM-6 – Configuration Settings","NIST SP 800-53 SI-10 – Information Input Validation","GDPR Article 32 – Security of Processing","OWASP Top 10 A03:2021 – Injection","OWASP Email Security Guidelines – HTML\u002FCSS Sanitization","published","2026-08-08T10:20:35.834102+00:00","2026-08-08T10:20:35.733+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fnew-css-attacks-can-break-webmail.html","new-css-attacks-can-break-webmail-defenses-to-steal-passwords-and-tokens-92a77f","New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"23b5dd1c-83b4-445a-97e8-db9f586377f8","2026-08-08","afternoon","ThreatNoir Weekend Brief — August 8","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-08\u002Fthreatnoir-afternoon-brief-2026-08-08.mp3"]