News

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-08-09 08:01:00 UTC

CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the s…

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styli… [+5338 chars]