{"data":{"id":"8befffda-5778-4fe2-a563-e98b09c73079","title":"ASCII smuggling crosses over from AI prompt injection to phishing evasion","summary":"Microsoft researchers discovered a phishing campaign using ASCII smuggling, a technique that hides invisible Unicode characters (special text codes) in emails to trick spam filters into missing malicious keywords like 'funding'. This technique was originally studied in AI security research as a way to hide instructions from people while exposing them to AI models, but attackers adapted it for traditional email phishing by splitting words that filters look for.","solution":"Microsoft built hunting logic for email-borne prompt injection and obfuscation patterns as part of Microsoft Defender for Office 365 prompt injection protection. A practical detection method is to search for messages carrying characters from the Unicode tags block (U+E0000-U+E007F), though the initial broad signature needed refinement with Unicode context to avoid flagging legitimate messages.","labels":["security","research"],"sourceUrl":"https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/","publishedAt":"2026-09-03T16:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["prompt_injection","rag_poisoning"],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft","Microsoft Defender for Office 365"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-03T16:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}