Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Research warning of “severe risks” when using AI therapy chatbots

UK launches a £500 million package to support diverse and underrated investors and founders

California creates a residential-focused agency | Planetizen News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cybercriminals abuse CSS to avoid spam filters and track email users’ actions
Identity

Cybercriminals abuse CSS to avoid spam filters and track email users’ actions

userBy userMarch 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 17, 2025Ravi LakshmananWeb Security/Cyber ​​Threats

CSS to avoid spam filters

Malicious actors are exploiting Cascade Style Sheets (CSS) used to style and format web page layouts, bypassing spam filters, and tracking user actions.

This states that, according to a new finding from Cisco Talos, such malicious activities can undermine the safety and privacy of victims.

“The features available in CSS allow attackers and spammers to track user actions and preferences, but some features related to dynamic content (e.g. JavaScript) are restricted to email clients compared to web browsers,” Talos Researcher Omid Mirzaei said in a report published last week.

This insight is based on previous findings from cybersecurity companies about a surge in email threats that utilize hidden text salt in late 2024 with the aim of circumventing email spam filters and security gateways.

This technique involves including comments that are not visible to the victim when rendered to an email client, and irrelevant content, particularly using legitimate features of Hypertext Markup Language (HTML) and CSS, but can trip down the parser and detection engine.

Cybersecurity

A recent analysis of TALOS found that threat actors use CSS properties such as Text_indent and Opacity to hide unrelated content from being visible to email institutions. The ultimate goal of these campaigns is, in some cases, to redirect email recipients to a phishing page.

CSS to avoid spam filters

Additionally, it has been revealed that CSS provides CSS with the opportunity to monitor user behavior via SPAM email by embedding CSS properties such as @Media CSS AT-Rule and opening the door to potential fingerprint attacks.

“This abuse ranges from identifying recipients’ font and color scheme preferences and client languages ​​to tracking actions (e.g., displaying and printing emails),” explained Mirzaei.

“CSS offers a wide range of rules and properties that can threaten spammer and threat actor fingerprint users, webmail or email clients, and systems. For example, Media At Rules can detect certain attributes of a user’s environment, such as screen size, resolution, and color depth.”

To mitigate the risk poses by such threats, we recommend implementing advanced filtering mechanisms to detect hidden text salting and content concealment and using email privacy proxy.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEqual1 unveils the world’s first silicon-based quantum server
Next Article Broadwick Group gets Camm & Hooper
user
  • Website

Related Posts

New Rowhammer Attack Variant Degrades AI Models on Nvidia GPUs

July 12, 2025

Over 600 laravel apps exposed to remote code execution due to app_keys leaked on github

July 12, 2025

Fortinet releases patches for important SQL injection defects in Fortiweb (CVE-2025-25257)

July 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Research warning of “severe risks” when using AI therapy chatbots

UK launches a £500 million package to support diverse and underrated investors and founders

California creates a residential-focused agency | Planetizen News

Baker Creek Pavilion: A blend of nature and architecture in Knoxville

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.