Filed under: Cybersecurity — Phishing — August 2026

What happened

Security researchers presenting at Black Hat USA showed a new attack technique that hides malicious HTML and CSS inside an email so it breaks out of its normal boundaries and messes with the mail program’s own interface. In one demonstrated chain against Outlook, the trick pops up a fake Microsoft sign-in box that looks like it belongs to the app itself and captures whatever password the reader types. A similar trick against Gmail was used to quietly send data out to an attacker’s server. This is proof-of-concept research only — the researchers found no evidence it has been used in real attacks yet, but the underlying flaws in Outlook and Gmail were still unpatched as of the August 6, 2026 publication date.

Why it matters to your business

Almost every Phoenix small business runs on Outlook, Gmail, or both, and this attack needs nothing more than the victim opening an email — no attachment, no link click required to start. Because the fake login box appears to come from inside a program employees already trust, it’s harder to spot than a typical phishing email, and it specifically targets the Microsoft 365 and Google Workspace credentials that unlock everything else in your business.

What to do this week

Make sure Outlook (desktop and web) and Chrome/Edge are set to auto-update, since fixes from Microsoft and Google will roll out as patches rather than a single big announcement. Remind staff that Microsoft 365 and Google will never ask for a password inside a pop-up that appears while simply reading an email — if a sign-in prompt shows up unexpectedly while previewing a message, close it and log in directly at office.com or google.com instead. If you haven’t already, turn on multi-factor authentication for every Microsoft 365 and Google Workspace account; it won’t stop every version of this attack, but it blocks the plain password theft variant cold.

The bigger picture

This is a reminder that browser-based email interfaces are their own attack surface, not just the messages inside them — the same category of trick showed up in this year’s Ubiquiti and hotel Wi-Fi login-hijack stories. — New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Not sure if your team would spot a fake login prompt? Book a free consult — https://micro1tech.com/contact/