← All issues

This Week In Email — August 12, 2026

Black Hat week delivered the story of the year: PortSwigger showed that malicious CSS — yes, CSS — can break out of the message body in essentially every major webmail client, capture passwords without a line of JavaScript, and prompt-inject the AI assistants reading your mail. Meanwhile Yahoo's feedback loop is duplicating complaints, Microsoft quietly blinded senders in SNDS and JMRP, an EWS deadline lands this month, and Costco just paid $14 million for urgency-baiting subject lines. Heavy week. Let's get into it.

In This Issue

Top Stories

CSS Is the Bomb Inside Your Inbox: PortSwigger Breaks Webmail Defenses Across Every Major Client

Security & Anti-Abuse — Gareth Heyes of PortSwigger published research out of Black Hat USA 2026 (August 6) demonstrating working attack chains against essentially every major webmail client — Gmail, Outlook, Yahoo, AOL, Fastmail, and Proton — using nothing but malicious CSS in an email. The chains are ugly: an Outlook/Firefox combination spoofs a Microsoft sign-in page and captures the typed password with zero JavaScript, a Yahoo/AOL "paste race" exposes a Medium login token, and a Gmail/Cowork chain prompt-injects an AI email assistant into exfiltrating a Slack token.

The root causes are twofold: CSS features webmail clients deliberately allow, and gaps between what sanitizers think they approved and what browsers actually render. Fastmail fixed two bugs and a Proton proxy bypass died on retest — but the Outlook label-jacking and Gmail's image-set() bypass still worked at publication.

The through-line worth sitting with: every AI tool granted read access to a mailbox inherits email's entire threat model, and this research hands attackers an injection channel that survives sanitization. Expect mailbox providers to get more aggressive about stripping "weird" HTML and CSS in response — if you design email for a living, watch for rendering changes as fixes ship. Your favorite styling channel is now a documented attack surface.

Sources: PortSwigger Research, The Hacker News, Dark Reading, Security Affairs, talk materials

Deliverability & Authentication

Yahoo Investigating CFL Malfunction: Duplicate Spam Complaints Flowing to Senders Since August 6

Yahoo says it's investigating a spike in complaint-report volume through its CFL (Complaint Feedback Loop) — since August 6, senders may be receiving duplicate complaints. If you alarm on complaint-rate thresholds or auto-suppress on FBL hits, sanity-check your numbers before reacting: that "spike" may be Yahoo's bug, not your list.

The quiet danger is downstream. Duplicate complaints can silently corrupt suppression logic and skew any dashboard that treats complaint counts as ground truth. Yahoo is asking for examples at mail-questions@yahooinc.com — if you've got clean evidence, send it.

Sources: Yahoo Postmaster blog, Yahoo Sender Hub CFL

Microsoft Strips Spam-Trap Data From SNDS, Moves JMRP to Header-Only ARF — Complaint Workflows Are Breaking

Catching up on a change that landed July 22 and slipped past most senders: SNDS Data Reports no longer show spam-trap hit counts — "to protect the integrity and effectiveness of our anti-abuse systems," per Microsoft. That was the early-warning signal for acquisition and hygiene problems. The trap hits still happen and still damage your reputation. You just can't see them anymore.

The nastier half: JMRP complaint reports are now header-only ARF — no complainant address, no message body. Any parser that keyed suppression off the body now fails silently. Complainants don't get suppressed, they complain again, and the reputation damage compounds. Attribution now has to come from Message-ID, DKIM selectors, and sending IP.

If you own the complaint-processing layer for any sending platform, audit it this week. A parser that fails silently is worse than one that fails loudly — you won't know it's broken until your Outlook reputation tells you.

Source: emailexpert

Gmail Postmaster Tools Now Warns in Writing at 0.1% Spam Rate

Another late-July change worth catching up on: Postmaster Tools' Deliverability analysis now issues an explicit warning when your spam rate exceeds 0.1%. Previously 0.1% was "aspirational" and 0.3% was the enforcement ceiling — and plenty of programs treated the space between as working room. That grey zone now has a warning light in it.

Worth remembering: reported spam rates understate reality, because mail that's already junked can't be complained about. If Postmaster Tools shows 0.1%, your true number is higher. Treat the warning as operational, not advisory.

Sources: emailexpert, companion piece

Infrastructure & MTAs

Exchange Online EWS: Allow-List Deadline Is August 31 — Then Default-Off October 1, Dead April 2027

If your org has anything still talking EWS (Exchange Web Services) — archiving tools, CRM connectors, migration utilities — the clock runs out this month. Admins who still need EWS must set EWSEnabled to true and create AppID allow lists by end of August. On October 1, EWS flips to disabled-by-default (null values convert to false), and April 1, 2027 is the full shutdown, "no exceptions." Microsoft may run temporary shutdowns along the way specifically to expose hidden dependencies.

Migrate to Graph or allow-list now. The last easy exit is this month — after October 1 you're debugging an outage instead of planning a migration. (On-prem Exchange is unaffected.)

Sources: Microsoft Tech Community, Computerworld

Security & Anti-Abuse

Arctic Wolf: M365 AitM Campaign Hunts Payroll and Finance Mailboxes

Arctic Wolf Labs detailed an active adversary-in-the-middle campaign that starts with voicemail-lure phishing and runs victims through a six-stage redirect chain — bouncing through Google Meet, Google Ads, and Amazon S3 links to defeat filters — before landing on AitM decoy pages. Stolen sessions are kept alive by automation on roughly 8-hour refresh cycles and hidden behind residential proxies, so the logins look like ordinary consumer traffic.

Post-compromise, the attackers use the Graph API to enumerate payroll, HR, and finance mailboxes and harvest banking mail. Hundreds of organizations hit across healthcare, education, manufacturing, government, and professional services in the US, Canada, and Europe — with overlap to Microsoft's Storm-2755 / "Payroll Pirate" cluster. If you handle payroll changes over email, this campaign is aimed directly at you.

Source: The Hacker News (Arctic Wolf Labs research)

Regulatory & Compliance

Costco Pays $14M Over False-Urgency Subject Lines — Washington Claims Close August 24

Costco settled Washington-state claims (CEMA plus the Consumer Protection Act) that subject lines like "Today is the last day to access Member-Only Savings" manufactured false urgency for promotions it knew would be extended. The class covers Washington residents who received Costco commercial email between June 2, 2021 and July 7, 2026; claims and exclusions are due August 24, with final approval October 2.

emailexpert's framing is the sharp one: Costco pays $14 million "and agrees to change nothing." But the precedent is the story — a state email statute with a private right of action just produced a very visible payout, and copycat suits follow payouts. If your lifecycle program leans on countdown-timer urgency for offers you routinely extend, that copy is now legal surface.

Sources: emailexpert, Fortune, Top Class Actions

Italy's Garante Flexes Twice: €2M for Lusha, €280K for One Unconfirmed-Registration Email

Two enforcement actions in one week, both aimed at practices the email industry leans on. Italy fined US-based B2B contact broker Lusha €2 million with deletion orders — asserting GDPR jurisdiction over data brokers with no EU establishment. That's a direct shot at the prospecting-data supply chain behind cold outreach: "we have no EU office" is no longer a shield.

Separately, the Garante fined Altroconsumo €280,000 for emailing a user who never confirmed their registration. Mailing an unconfirmed signup is now demonstrably a six-figure event in at least one EU market. Confirmed opt-in just moved from best practice toward compliance requirement.

Sources: emailexpert on Lusha, emailexpert on Altroconsumo

Links Worth Your Time

Events & Community

That's the week. If something is wrong, reply and tell me — I read every response. Better yet, hit "forward" and send this to a colleague who owns a complaint parser.

— John


This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.