Tag

Email Security

All articles tagged with #email security

Invisible Unicode Tricks Power Large-Scale Phishing Campaign
technology1 month ago

Invisible Unicode Tricks Power Large-Scale Phishing Campaign

Microsoft warns of a large-scale phishing campaign that hides messages by embedding invisible Unicode characters (ASCII smuggling) in finance-related words to evade filters; peak volume reached about 2.37 million daily messages in February and persisted into May; the campaign used ActiveCampaign infrastructure and was detected by Defender using other signals; defenders should normalize Unicode tag characters before detection and even before feeding content to AI to curb prompt-injection risks.

Phishing Goes Incognito: Invisible Unicode Tricks Evade Filters
technology1 month ago

Phishing Goes Incognito: Invisible Unicode Tricks Evade Filters

Microsoft uncovered a massive phishing campaign that used invisible Unicode tag characters to hide content and split keywords, a form of ASCII smuggling that can bypass filters and extend beyond AI prompts into traditional email scams. The campaign peaked at 2.37 million messages in late February from finance-themed domains with weekday bursts and weekend lulls, and declined thereafter. Defenders are advised to normalize/tokenize to strip non-rendering Unicode points and monitor behavioral patterns like weekday-on/weekend-off activity.

Invisible Unicode tricks fuel spam as ASCII smuggling widens its reach
technology1 month ago

Invisible Unicode tricks fuel spam as ASCII smuggling widens its reach

An Ars Technica piece explains how “ASCII smuggling” uses invisible Unicode tag characters to hide malicious prompts in emails, enabling spammers to evade filters and trick AI detectors. Microsoft Defender logged a sharp spike in ASCII-smuggling signatures in early 2026, highlighting that traditional keyword searches and even some ML-based spam detectors can miss these hidden tokens unless filters are updated to account for invisible characters or use OCR-like analysis.

Phishers weaponize Apple change alerts to push fake iPhone scams
technology5 months ago

Phishers weaponize Apple change alerts to push fake iPhone scams

A phishing campaign uses legitimate Apple account-change emails to push a fake iPhone purchase alert, embedding the scam text into user-provided Apple ID name fields so the message appears authentic; when recipients call the supplied number, they risk remote access or data theft. The emails pass SPF/DKIM/DMARC, and are delivered from Apple infrastructure, highlighting how attackers abuse legitimate features to bypass filters. Users should be wary of unexpected purchase notices and verify changes via official Apple channels.

Global cloud-storage scam hits inboxes with fake renewal alerts to steal payment details
cybersecurity8 months ago

Global cloud-storage scam hits inboxes with fake renewal alerts to steal payment details

A worldwide phishing campaign floods recipients with urgent emails claiming cloud-storage renewals failed, pushing them to a fake Google Cloud Storage link that redirects to scam pages impersonating cloud portals. The pages upsell a deceptive “loyalty” upgrade and collect credit card info, with the aim of affiliate revenue. Legitimate providers do not notify via such scans or require third-party security products, and users should delete the messages and verify billing directly on official sites.

Beware of Malicious SVG Files in Phishing and Email Attacks
security1 year ago

Beware of Malicious SVG Files in Phishing and Email Attacks

Cybercriminals are increasingly using SVG image files in emails to deliver malware like AsyncRAT, which can remotely control devices. These malicious SVGs often appear in emails from trusted sources and contain embedded scripts that evade traditional security measures. Users are advised to delete any emails with SVG attachments unless they are certain of their legitimacy, as these files pose a significant security threat.

Google AI email summaries vulnerable to phishing hacks
technology1 year ago

Google AI email summaries vulnerable to phishing hacks

Researchers have discovered a vulnerability in Google's Gemini AI used in Workspace that allows attackers to embed hidden commands in email summaries, potentially leading to phishing attacks. Google is working on defenses, but users are advised to verify AI-generated content, avoid using summaries for suspicious emails, keep software updated, and consider disabling Gemini summaries temporarily to stay safe.

Google Gemini Vulnerability Enables Hidden Phishing in Gmail
technology1 year ago

Google Gemini Vulnerability Enables Hidden Phishing in Gmail

Security researchers have discovered a vulnerability in Google Gemini for Workspace that allows attackers to embed hidden malicious instructions in emails, which can manipulate the AI assistant to display fake security warnings and facilitate credential theft and social engineering attacks. The attack exploits the AI's processing of crafted HTML and CSS to hide instructions, affecting multiple Google Workspace products and potentially enabling AI-driven worms. Organizations are advised to implement mitigation strategies such as HTML sanitization and user awareness training.

Google Gemini flaw enables email summary phishing attacks
technology1 year ago

Google Gemini flaw enables email summary phishing attacks

Google's Gemini AI in Workspace can be exploited through hidden prompt injections in emails to generate convincing phishing warnings or malicious instructions, posing security risks. Despite safeguards, attackers can embed invisible directives using HTML and CSS, which Gemini obeys when summarizing emails, potentially leading users to trust malicious content. Google is working on defenses, but users should remain cautious and not rely solely on Gemini summaries for security alerts.

Google's AI-Enhanced Gmail and Workspace: What You Need to Know
technology1 year ago

Google's AI-Enhanced Gmail and Workspace: What You Need to Know

Google's latest Gmail upgrade introduces AI-powered smart replies and access to all past emails and files, raising privacy concerns. Users are encouraged to adopt new privacy tools like Apple's Hide My Email and Google's Shielded Email to protect against data breaches and phishing attacks. The article emphasizes the importance of masking email addresses and adopting secure practices amid increasing AI-driven cyber threats, suggesting a shift towards more private and secure email solutions.

Google's AI and Gmail: The Future of Your Digital Life
technology1 year ago

Google's AI and Gmail: The Future of Your Digital Life

Google's latest Gmail update introduces AI-powered smart replies and access to past emails and files, raising privacy concerns. New privacy features like Shielded Email aim to mask addresses and protect users from breaches, but users should consider creating new email accounts for enhanced security. A survey indicates many users prefer privacy-focused services like Proton Mail over Gmail, highlighting ongoing privacy tensions in email use.

Hackers Exploit Corrupted Files to Bypass Antivirus Protections
cybersecurity1 year ago

Hackers Exploit Corrupted Files to Bypass Antivirus Protections

Cybersecurity researchers have identified a phishing campaign that uses corrupted Microsoft Office documents and ZIP archives to bypass email defenses and antivirus software. These corrupted files evade detection by exploiting built-in recovery mechanisms in programs like Word and Outlook, allowing malicious emails to reach users' inboxes. The attack, active since at least August 2024, aims to trick users into opening these files, which contain QR codes leading to malware or credential theft sites. This highlights the ongoing evolution of phishing tactics to circumvent security measures.