// Microsoft 365MEDIUM
Security researcher Gareth Heyes disclosed CSS bomb attack techniques affecting multiple webmail services including Outlook. The attacks exploit HTML and CSS sanitization discrepancies to manipulate user interfaces, leak authentication tokens, and capture passwords. Some Outlook-specific vulnerabilities including UI manipulation and interface spoofing were noted as unresolved at publication time, though other services addressed reported issues.
// Get alerts for Microsoft 365