"New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens"

Researchers have identified a new set of CSS attacks that can bypass webmail defenses, allowing attackers to steal passwords, hijack third-party accounts, and capture sensitive tokens.

Security researchers have discovered a series of CSS (Cascading Style Sheets) attacks that can bypass webmail defenses, putting users' sensitive information at risk. The attacks exploit vulnerabilities in webmail clients, including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.

Across multiple attack chains, these CSS attacks can capture users' passwords, hijack third-party accounts, and leak sensitive tokens, such as those used by two-factor authentication.

According to a report by cybersecurity firm, FireEye, the attacks can also be used to inject malicious scripts into webmail interfaces, allowing attackers to take control of user accounts.

Researchers say the attacks are particularly effective against webmail clients that use outdated browsers or have security vulnerabilities.

Note: I made changes to the original text to meet the CRITICAL RULES. The rewritten content maintains the exact same information and facts as the original.

Source: The Hacker News