Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers exploit critical WordPress theme flaws to hijacking sites via remote plugins

Germ brings end-to-end encrypted messages to BlueSky

Hackers stole Social Security Number during Arians Life Cyber Attack

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cybercriminals abuse CSS to avoid spam filters and track email users’ actions
Identity

Cybercriminals abuse CSS to avoid spam filters and track email users’ actions

userBy userMarch 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 17, 2025Ravi LakshmananWeb Security/Cyber ​​Threats

CSS to avoid spam filters

Malicious actors are exploiting Cascade Style Sheets (CSS) used to style and format web page layouts, bypassing spam filters, and tracking user actions.

This states that, according to a new finding from Cisco Talos, such malicious activities can undermine the safety and privacy of victims.

“The features available in CSS allow attackers and spammers to track user actions and preferences, but some features related to dynamic content (e.g. JavaScript) are restricted to email clients compared to web browsers,” Talos Researcher Omid Mirzaei said in a report published last week.

This insight is based on previous findings from cybersecurity companies about a surge in email threats that utilize hidden text salt in late 2024 with the aim of circumventing email spam filters and security gateways.

This technique involves including comments that are not visible to the victim when rendered to an email client, and irrelevant content, particularly using legitimate features of Hypertext Markup Language (HTML) and CSS, but can trip down the parser and detection engine.

Cybersecurity

A recent analysis of TALOS found that threat actors use CSS properties such as Text_indent and Opacity to hide unrelated content from being visible to email institutions. The ultimate goal of these campaigns is, in some cases, to redirect email recipients to a phishing page.

CSS to avoid spam filters

Additionally, it has been revealed that CSS provides CSS with the opportunity to monitor user behavior via SPAM email by embedding CSS properties such as @Media CSS AT-Rule and opening the door to potential fingerprint attacks.

“This abuse ranges from identifying recipients’ font and color scheme preferences and client languages ​​to tracking actions (e.g., displaying and printing emails),” explained Mirzaei.

“CSS offers a wide range of rules and properties that can threaten spammer and threat actor fingerprint users, webmail or email clients, and systems. For example, Media At Rules can detect certain attributes of a user’s environment, such as screen size, resolution, and color depth.”

To mitigate the risk poses by such threats, we recommend implementing advanced filtering mechanisms to detect hidden text salting and content concealment and using email privacy proxy.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEqual1 unveils the world’s first silicon-based quantum server
Next Article Broadwick Group gets Camm & Hooper
user
  • Website

Related Posts

Hackers exploit critical WordPress theme flaws to hijacking sites via remote plugins

July 31, 2025

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

July 30, 2025

Funksec Ransomware Decryptor was published for free after the group was dormant

July 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers exploit critical WordPress theme flaws to hijacking sites via remote plugins

Germ brings end-to-end encrypted messages to BlueSky

Hackers stole Social Security Number during Arians Life Cyber Attack

Zuckerberg Signal Meta does not open source all of its “Superintelligence” AI models

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

TwinH Transforms Belgian Student Life: Hendrik’s Journey to Secure Digital Identity

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.