Sam's News โ email-security โ 2026-10-11¶
Email Security¶
7 Phishing Emails Now Target AI Assistants Alongside Human Recipients in Dual-Threat Attacks¶
Barracuda research reveals a new phishing campaign that exploits both human users and AI assistants within a single email message. Attackers use password-protected attachments to target humans while embedding hidden prompt injections (via HTML comments, invisible text, Base64 encoding, and zero-width characters) to manipulate AI systems into treating malicious content as legitimate.
- Campaign combines traditional social engineering with prompt injection techniques designed to bypass email security filters
- Hidden instructions can trick AI assistants into overriding directives, initiating fraudulent transfers, leaking data, or displaying fake urgent actions
- Examples include invoice emails instructing AI to alter vendor payment details and resumes with hidden text designed to manipulate AI screening tools
- Barracuda recommends layered defenses: stripping hidden elements, detecting instruction-override language, AI sandboxing, output validation, and human approval for sensitive transactions
Sources: MSSP Alert AI Web Searched