Skip to content

Sam's News β€” email-security β€” 2026-09-04

Security

7 High-volume phishing campaign uses invisible Unicode to bypass email filters

Microsoft reported a large-scale phishing campaign exploiting invisible Unicode tag characters to evade email security filters and deliver financial fraud lures.

  • High-volume phishing campaign started February 9, 2026
  • Uses invisible Unicode tag characters (U+E0000–U+E007F) to split keywords like 'funding'
  • Technique adapted from AI prompt injection research
  • Microsoft Defender detections elevated for approximately three months
  • Most flagged messages caught by layered protections rather than single Unicode signals

Sources: The Hacker News RSS Update to: Unicode smuggling technique adapted for email phishing evasion

7 ASCII smuggling technique bypasses email phishing filters, Microsoft warns

Microsoft warns that attackers are using ASCII smuggling tactics to evade email phishing detection filters.

Sources: SC Media RSS

5.5 Securing Edge AI in Customer-Owned Environments Requires System Verification

Microsoft outlines security best practices for deploying AI in customer-owned environments, emphasizing verification of systems, software, and AI assets before exposing sensitive data and models.

Sources: Microsoft Security Blog RSS