Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBER RISK THREAT INTELLIGENCE VULNERABILITIES & THREATS NEWS CSS: The Hidden Threat Lurking in Your Inbox CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared. Kristina Beek,Associate Editor,Dark Reading August 5, 2026 3 Min Read SOURCE: ALUBALISH VIA GETTY IMAGES Black Hat USA 2026 – Las Vegas – Using email platforms to target users is nothing new in the world of threat actors. Nor is it revolutionary for defenders who've shored up guardrails when it comes to suspicious attachments, malicious JavaScript, and more. But as these well-known threats take command of everyone's attention, another vector remains hidden in plain sight. While HTML is the structure that powers web pages, Cascading Style Sheets (CSS) address design and presentation of the page. From the text to colors and tags to images, CSS manages how a page is displayed. And according to Gareth Heyes, Web security researcher at PortSwigger, it can be weaponized because of its multiple capabilities. LOADING... "It's almost like a programming language now," Heyes says. "CSS was on the back burner and largely ignored. [Now] CSS and HTML alone — no JavaScript, no attachments — are enough to build a working keylogger" stealing sensitive and confidential user information. Related:Angola's Largest Telco Breached Hours Before IPO Design Discoveries Heyes first discovered the red flags when he was looking into designing his own website, experimenting with personal projects, and uncovering how much power CSS had, especially when used maliciously. But despite its well of potential threats, CSS-based attacks still require more effort than the traditional email-based exploits. "You've got to work a bit harder because although [CSS is more] powerful, it takes more work to work out how to get data out of there using animations and that sort of thing," he adds. LOADING... Though this field remains largely untapped, Heyes believes that CSS-based attacks will become the next big frontier due to the fact that they can bypass executing script and because people aren't paying enough attention. "What the browsers are doing all the time is adding new features to CSS, to HTML," notes Heyes. "But the problem is, as you add those features, the attack surface grows." CSS Is Here to Stay As for seeing these kinds of vulnerabilities and attacks in the wild, Heyes plans on revealing his findings during his briefing at Black Hat USA this week, but confirms that he found flaws in big names that many will be familiar with. And the responsibility ultimately lies with these companies, as there's not much users can do on their end unless they happen to have knowledge of HTML and CSS at their disposal. When a user receives an email with malicious CSS display features while using webmail, they're effectively locked in. "You can't turn off CSS," says Heyes. "But from a webmail perspective, you can basically isolate the messages using a technology so that it can't interfere with the rest of the page. And webmail can also produce a more effective sanitization of the CSS in order to prevent it from leaking out of the page, breaking out of the trust boundaries of the message." Related:Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook What he hopes for moving forward is that these webmail vendors will correctly filter and sanitize their user displays and that security teams will use an image proxy to protect users — guardrails that are clearly necessary considering Heyes says that in his research he's found hijacking bugs, various advanced attacks methods, and even bugs in vendors' webmail platforms. This hope may be misplaced, however, as Heyes' research journey reveals a troubling pattern in how major email platforms handle security disclosures. Some vendors responded swiftly and transparently. Others dismissed the findings entirely, only to quietly implement fixes later without acknowledgment. So, while some are ready to face the new frontier, others are seemingly more comfortable not acknowledging its realities. But with research showing that it's already here, it appears that CSS and its attack surface isn't waiting for anyone. Black Hat USA AUG 1, 2026 TO AUG 6, 2026 | MANDALAY BAY CONVENTION CENTER, LAS VEGAS, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS Read more about: Black Hat News About the Author Kristina Beek Associate Editor, Dark Reading Kristina Beek is associate editor at Dark Reading, where she covers a wide range of cybersecurity topics and spearheads video-related content, where she contributes both content and production skills to Dark Reading's expanding video coverage. She is the creator and host of the Heard It From a CISO video series, where she interviews CISOs, directors, and other industry strategists to provide insights into the ever-evolving cybersecurity landscape. In addition to her editorial work, Kristina manages Dark Reading's social media channels (including social video), and has held numerous roles within Dark Reading over the years, including copy editor and breaking news reporter, before transitioning her focus to multimedia journalism. Kristina graduated from North Carolina State University in 2021 with a degree in Political Science, concentrating in law and justice, and a minor in English. During her time at NC State, she honed her writing skills by contributing opinion pieces to the university's newspaper, as well as writing fiction, poetry, and short essays. Upon graduating, she began her career as a content editor, focusing on higher education topics before joining Dark Reading in December of 2022. Currently based in Washington D.C., you can find Kristina reading, taking walks in Georgetown, trying all the restaurants she can, and taking pictures of all the dogs she sees. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Black Hat USA Coverage ENDPOINT SECURITY 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning byNate Nelson AUG 5, 2026 5 MIN READ APPLICATION SECURITY AI Harnesses Burst With Potential Exploit Opps byRobert Lemos JUL 30, 2026 4 MIN READ CYBERSECURITY OPERATIONS Red Agents vs. Blue Agents: How to Make AI Better at Defense byRob Wright JUL 29, 2026 5 MIN READ APPLICATION SECURITY When AppSec Scanners Become a Supply Chain Attack Vector byEricka Chickowski JUL 29, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices