Phishing expands ASCII smuggling beyond AI
Microsoft finds invisible Unicode tags used to hide financial-lure words in a massive email phishing campaign.
Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing. Microsoft uncovered a massive phishing campaign using invisible Unicode tag characters that peaked at more than 2.37 million messages in late February, remained elevated during weekdays over the next three months, and gradually declined by mid-June.
Sources
- The Register Original source
Continue Reading
IDScan Lawsuits Grow Over ID Data Leak
Multiple lawsuits target IDScan after alleged breach exposed 153M driver's licenses for sale on dark web.
Unicode Trick Fuels Million-Email Phishing Surge
A campaign hides 'funding' lure words with invisible Unicode tags, splitting keywords to slip past filters.
French hospital fined €500,000 after breach exposes data of 727,000
CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.