Act
active
ASCII smuggling technique migrates from AI prompt injection to phishing evasion
- Engineer — Plan: Audit email security gateway and content-inspection rules to detect invisible Unicode characters used to bypass filters; evaluate whether your email platform has updated signatures for this evasion class.
- SOC/IR — Act: Build or tune detection rules to flag emails containing invisible/tag Unicode codepoints (U+E0000 range); hunt for recent phishing lures that may have bypassed filters using this technique since the evasion method is now publicly documented.
- Leader — Learn: A novel phishing evasion technique is gaining traction; no board-level action needed now, but awareness is useful context for the next email security or AI-risk discussion.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.