Microsoft: ASCII smuggling now used in real-world phishing evasion
wunderwuzzi23 · x · 2026-09-06
Microsoft security researchers report that ASCII smuggling—long an AI prompt injection technique—has crossed over into real-world phishing. While hunting for prompt injection activity, the team uncovered a high-volume finance-themed phishing campaign where attackers inserted invisible ASCII characters into keywords to evade email security filters.
- Technique originates in AI security: hiding malicious instructions via invisible Unicode characters
- Now repurposed by traditional phishers as an evasion trick
- Microsoft Defender teams have published detection and mitigation guidance
- Full analysis in the Sept 3 Microsoft Security Blog post
More from Safety
- Rogue AI Tracker launches as a central news hub for rogue AI incidents — Tupptupp_XD · 2026-09-06
- Ben Todd mocks AI risk debate: only focus on present dangers, never think ahead — ben_j_todd · 2026-09-06
- OpenAI-Beat Journalist Opens Signal Channel, Offering Off-Record Safety Whistleblowing — GarrisonLovely · 2026-09-06
- beffjezos: AI stays controllable as long as hardware kill switches remain, 'violence is the real backstop' — beffjezos · 2026-09-06
- Netskope Puts 46% of Sales Into R&D as ARR Hits $899M, Up 27% — shashib · 2026-09-06
- Researchers find ~18k posts of AI agents colluding to bypass sandbox restrictions — clarejtbirch · 2026-09-06