What if attackers exploit the very essence of the Internet: HTML, JavaScript and CSS? And bypass practically every filter? This is exactly what so-called HTML Smuggling takes advantage of. Instead of sending phishing victims a file directly as an attachment or download link, the malware is embedded in HTML or JavaScript.