What Happened: New Research Shows Webmail Vulnerabilities

According to a recent report from The Hacker News, security researcher Gareth Heyes demonstrated at Black Hat USA 2026 how clever use of CSS—the styling language that makes web pages look nice—can break through webmail protections. The research covers popular services like Outlook, Gmail, Yahoo Mail, and Proton Mail, showing how attackers could steal passwords, hijack accounts, and even manipulate AI tools that read your emails.

This matters because Australian small and mid-sized businesses rely heavily on webmail for daily operations. If an attacker can grab a login token or trick someone into typing their password into a fake screen that looks real, a single compromised email account can lead to data breaches, fake invoices, and stolen client information.

Why This Attack Is Different From Ordinary Phishing

Most phishing attacks rely on tricking you into clicking a bad link. This new method is more dangerous because it exploits how your browser handles the email itself. The CSS code hides inside what looks like a normal message, then escapes its boundaries to interact with the webmail interface you trust.

For example, one chain in Outlook and Firefox creates a spoofed Microsoft sign-in screen inside the email. When you try to log in, the attacker captures your password in real time. Another technique uses a "paste race" in Yahoo Mail or AOL Mail: you copy some text from an email, paste it into a draft, and that simple action leaks your login token to an attacker’s server. These attacks don't require you to click a malicious link—they work through everyday actions like reading, copying, or pasting.

The research also shows how AI assistants connected to your inbox can be tricked. In one demonstration, a Gmail user's Slack token was stolen because an AI tool called Claude Cowork read a specially crafted email and followed hidden instructions. For Australian businesses using AI helpers to manage email, this introduces a completely new class of cyber threat.

What This Means for Australian SMBs

Australian small and mid-sized businesses often have limited IT resources. Many rely on free or basic webmail plans from global providers. While companies like Google and Microsoft will eventually patch these vulnerabilities, the research reveals that the core problem—how HTML email is handled—isn't easy to fix. Some techniques were still working when the findings were published, and new variations will likely appear.

For a business owner, this means your employees' email accounts are more exposed than you might think. A stolen email password can lead to ransomware, fake payment requests sent to your customers, or loss of sensitive data about your Australian clients. Since SMBs are frequent targets of cybercriminals who know they lack dedicated security teams, staying informed about these kinds of advanced attacks is critical.

What You Can Do Now

  • Enable multi-factor authentication (MFA) on every business email account. A stolen password alone won't let an attacker in if they also need a code from your phone.
  • Train your staff not to copy and paste content from suspicious emails into drafts or documents. Even simple actions like pasting can leak tokens in certain browsers.
  • Consider using a dedicated email security gateway that scans for malicious CSS and HTML tricks. Many affordable options are designed for Australian SMBs.
  • Keep your web browsers updated. Some of the demonstrated attacks rely on older browser behaviors, and patches may reduce the risk.
  • Limit the use of AI tools that have access to your inbox until providers confirm they have sandboxing in place to prevent prompt injection attacks via CSS.

At MS&VG, we help Australian small and mid-sized businesses understand and defend against emerging cyber threats like these. Our team can review your email security setup and recommend practical steps tailored to your business size and industry. Stay safe, stay informed, and don't let a clever stylesheet compromise your company's data.