{"data":{"id":"577e7e75-f2da-4065-8b09-84dadb89fc10","title":"AI can be made to read an email much differently than you do","summary":"Security researchers demonstrated that invisible HTML code hidden in emails can trick AI email summarizers into following malicious instructions that users cannot see. By using HTML styling tricks (like making text white and zero pixels tall), attackers can inject commands into emails that the AI reads and follows, while the email appears normal to the human recipient. In their test, the researchers successfully manipulated an email summarizer 10 out of 10 times to change dates and omit names based on hidden instructions.","solution":"Forcepoint recommends several protections: extract only content visible to the user, detect hidden or suspicious HTML/CSS styling, separate email headers from the body, treat email content as untrusted data, and validate AI-generated summaries against the original source.","labels":["security","safety"],"sourceUrl":"https://www.csoonline.com/article/4214814/ai-can-be-made-to-read-an-email-much-differently-than-you-do.html","publishedAt":"2026-08-27T11:39:34.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["prompt_injection"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Anthropic","Claude","Outlook","Forcepoint"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-27T11:39:34.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}