Microsoft: ASCII smuggling now used in real-world phishing evasion

wunderwuzzi23 · x · 2026-09-06

Microsoft security researchers report that ASCII smuggling—long an AI prompt injection technique—has crossed over into real-world phishing. While hunting for prompt injection activity, the team uncovered a high-volume finance-themed phishing campaign where attackers inserted invisible ASCII characters into keywords to evade email security filters.

Original post →

More from Safety

Safety channel →