View all sources for this day →

The Signal

This limited retained coverage pairs research into webmail trust boundaries with a phishing incident involving mailbox access. Together, they make email interfaces and identity workflows the focus of this packet without characterizing the broader security environment. [1][2]

Must Know

Webmail CSS attacks on AI email tools

AI & Agents · Research

What happened

PortSwigger researcher Gareth Heyes reported CSS-based attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail that can steal credentials or tokens, hijack sessions, and affect AI tools connected to inboxes. [1]

The reported attacks exploit webmail rendering of untrusted HTML/CSS in trusted interfaces, either through permitted CSS features or gaps between sanitizer decisions and browser rendering. [1]

Why it matters

The research reports an indirect prompt-injection chain through Claude Cowork and a connected Gmail integration: an injected instruction retrieved a token and placed it in an HTML draft, whose viewing leaked the token. [1]

IEH phishing and data-exposure report

Identity · Incident

What happened

IEH Corporation, a U.S. defense and aerospace manufacturer, disclosed that a phishing attack compromised an employee’s Microsoft 365 mailbox. [2]

The attack used a link impersonating a Microsoft document-sharing link; the employee entered Microsoft 365 credentials into a fraudulent login page, giving the attacker unauthorized mailbox access. [2]

Why it matters

The compromised mailbox contained emails and attachments, customer data, engineering documents, and potentially export-controlled information; no data exfiltration was confirmed. [2]

Sources (2)
  1. [1] Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

    securityaffairs · August 9, 2026

  2. [2] U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

    securityaffairs · August 9, 2026