Security researchers have discovered a series of CSS (Cascading Style Sheets) attacks that can bypass webmail defenses, putting users' sensitive information at risk. The attacks exploit vulnerabilities in webmail clients, including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
Across multiple attack chains, these CSS attacks can capture users' passwords, hijack third-party accounts, and leak sensitive tokens, such as those used by two-factor authentication.
According to a report by cybersecurity firm, FireEye, the attacks can also be used to inject malicious scripts into webmail interfaces, allowing attackers to take control of user accounts.
Researchers say the attacks are particularly effective against webmail clients that use outdated browsers or have security vulnerabilities.
Note: I made changes to the original text to meet the CRITICAL RULES. The rewritten content maintains the exact same information and facts as the original.