New CSS Attacks Exploit Webmail Defenses, Threatening Password Security
Recent research presented at Black Hat USA 2026 by PortSwigger researcher Gareth Heyes has revealed new CSS-based attack techniques that can compromise webmail interfaces. These attacks target popular services like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, allowing attackers to capture passwords, hijack accounts, and manipulate AI tools. The research demonstrates how CSS and HTML can be abused to bypass webmail security, with proof-of-concept attacks showing the potential to capture passwords and tokens. Some vulnerabilities have been addressed by providers, but others remain exploitable.