CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Keyloggers

A new class of email-based attacks that exploit ordinary CSS styling code to hijack webmail interfaces, spy on user activity, and even steal passwords in real time, all without relying on JavaScript or traditional malware. Dubbed “CSS bomb” attacks, the technique weaponizes trusted formatting features found in nearly every major webmail platform, turning a routine […]

This article has been indexed from Cyber Security News

Read the original article: