
PortSwigger revealed at Black Hat 2026 that a single email can render a fake login screen inside Outlook and steal passwords. Gmail and Yahoo are also affected.
🎯 How it works:
1. Send an email with hidden CSS styling code that bypasses filtering systems.
2. The code escapes the message area and takes control of the email client interface.
3. It renders a fake login screen — no links need to be clicked.
4. Result: The password you type flows straight to the hacker immediately.
⚠️ Lessons for you:
• Do not type passwords in pop-ups from an email — open the app directly and check the URL.
• Turn off automatic image downloads in Gmail and Outlook.
• Do not copy text from strange emails to paste elsewhere.
[Insight: “Don’t click suspicious links” is no longer enough. The application interface itself can lie.]
Kun Long
Author at The Sharing KH