VulnerabilitiesCSS Attacks in Webmail Can Steal Tokens and Manipulate AI Agents
Research published on August 9, 2026 by Gareth Heyes, a PortSwigger researcher, describes attacks that can be carried out using only HTML/CSS against
VulnerabilitiesResearch published on August 9, 2026 by Gareth Heyes, a PortSwigger researcher, describes attacks that can be carried out using only HTML/CSS against
VulnerabilitiesChina initiates cybersecurity review of Palo Alto Networks products to protect critical infrastructure, amid geopolitical tensions and tech self-reliance push.
VulnerabilitiesMalware can exploit Windows Hello for Business to maintain persistent access to Microsoft Entra ID without admin privileges. Learn about detection and mitigations.
VulnerabilitiesHead Mare compromises TrueConf servers, distributing PhantomCore malware via malicious clients. Vulnerable versions need immediate updates.
VulnerabilitiesDiscover how CSS attacks in webmail can compromise passwords, tokens, and AI agents, as revealed at Black Hat USA 2026, affecting major email services.
VulnerabilitiesPortSwigger has introduced HTTP Terminator , an AI-assisted research system developed by James Kettle to generate and validate HTTP desynchronization
VulnerabilitiesCritical Kemp LoadMaster flaw CVE-2026-8037: 792 exploitation attempts detected. Unauthenticated command injection; apply patches urgently.
VulnerabilitiesCritical zero-day SQL injection in Metabase allows data theft from cloud and self-hosted instances. Updates and mitigation steps provided.
VulnerabilitiesLearn about CPDLC vulnerabilities in ATN-B1 systems, including fake messages and disconnections from CISA advisory ICSA-26-219-01. CVE details included.