ASCII smuggling isn't just an AI security risk
ID: b0ddb69d-d1b5-56f3-97c7-b75df5509706
STIX ID: report--b0ddb69d-d1b5-56f3-97c7-b75df5509706
Feed Name: The Register (Security)
Microsoft researchers uncovered a large phishing campaign that inserted invisible Unicode tag characters into financial keywords (ASCII smuggling) to evade keyword and signature filters; the activity produced weekday-peaking volumes that reached over 2.37 million messages and persisted with a gradual decline through mid-June. Defenders are advised to normalize and strip non-rendering Unicode code points before keyword/signature evaluation and to watch behavioral indicators such as high-volume, finance-themed disposable domains with a weekday-on/weekend-off pattern.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
