CSS Email Attacks Can Steal Passwords Without JavaScript
PortSwigger research shows how sanitized CSS in webmail can cross the message boundary, spoof login forms, and capture passwords. Learn the exposure levels and what to do.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 24, 2026
PortSwigger research shows how sanitized CSS in webmail can cross the message boundary, spoof login forms, and capture passwords. Learn the exposure levels and what to do.
GitGuardian found 321 reachable n8n instances still accepting API tokens leaked in public GitHub commits. Revoke exposed keys, audit workflows and executions, and rotate…
See what is verified about WARDEN Stealer, how cookies, passwords, wallets, and clipboard data may be exposed, and what to do after a suspected…
The Keyv npm worm poisoned hundreds of packages and can react when a stolen GitHub token is revoked. Check persistence first, then rotate credentials…
See what is verified about Heisenberg RAT, how hidden desktops can expose browser sessions, and how to isolate, scan, and recover accounts safely.
Unit 42 showed how malware on Chrome for Windows can abuse synced Google passkeys. Learn who is affected, what was fixed, and how to…
N-central CVE-2026-18577 is under active attack. Install 2026.3.1.7, then check Take Control logs, Cloudflared services, and downstream endpoints.
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure, Linux persistence, stolen secrets, and the right recovery order.
Rails patched CVE-2026-66066 in Active Storage. Check whether your app uses vulnerable libvips processing, update, rotate exposed secrets, and inspect official forensic evidence.