Security researchers from PortSwigger disclosed CSS bomb attacks that exploit CSS styling code in email to hijack webmail interfaces and steal credentials. The technique affects Gmail, Outlook, Yahoo Mail, AOL Mail, Fastmail, and ProtonMail. Attackers use CSS quirks and pseudo-elements to turn emails into invisible keyloggers that capture passwords in real-time. Some flaws have been patched after bug bounty disclosure, but others remain unresolved.
// Service
Google Workspace
Google Workspace email, Drive, and identity for businesses, schools, and clinics.
// Alerts
Recent threats
// Google WorkspaceMEDIUM
Security researchers disclosed techniques called Pass-ta-key that can bypass biometrics protections in Google Password Manager, potentially allowing attackers to hijack the password manager and steal passkeys and stored credentials. The research was published on August 4, 2026.
Google revealed an ongoing data theft campaign attributed to Chinese nation-state actors (UNC6508/INFINITERED) exploiting Google Workspace security to target a diverse set of national, state, and private medical entities, including research and defense organizations. The campaign represents active exploitation affecting high-value targets across critical sectors.