The Signal
Must Know
Webmail CSS attacks on AI email tools
What happened
PortSwigger researcher Gareth Heyes reported CSS-based attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail that can steal credentials or tokens, hijack sessions, and affect AI tools connected to inboxes. [1]
The reported attacks exploit webmail rendering of untrusted HTML/CSS in trusted interfaces, either through permitted CSS features or gaps between sanitizer decisions and browser rendering. [1]
Why it matters
The research reports an indirect prompt-injection chain through Claude Cowork and a connected Gmail integration: an injected instruction retrieved a token and placed it in an HTML draft, whose viewing leaked the token. [1]
IEH phishing and data-exposure report
What happened
IEH Corporation, a U.S. defense and aerospace manufacturer, disclosed that a phishing attack compromised an employee’s Microsoft 365 mailbox. [2]
The attack used a link impersonating a Microsoft document-sharing link; the employee entered Microsoft 365 credentials into a fraudulent login page, giving the attacker unauthorized mailbox access. [2]
Why it matters
The compromised mailbox contained emails and attachments, customer data, engineering documents, and potentially export-controlled information; no data exfiltration was confirmed. [2]