Urgent.News

What's breaking now, across thousands of outlets.

Tech

What is ASCII smuggling, and how is it helping spammers bypass AI email filters?

What is ASCII smuggling, and how is it helping spammers bypass AI email filters?

ASCII smuggling is an evasion technique used by spammers to bypass AI-powered email spam filters. As AI systems and email filters have become more advanced, spammers have turned to sophisticated methods to get around detection. ASCII smuggling involves inserting invisible Unicode tag characters into email content, which prevents filters from properly processing the text.

These tags are readable by computers but nearly invisible to humans, allowing spammers to hide malicious content without raising suspicion. Microsoft researchers observed a significant increase in ASCII smuggling during a phishing campaign in February 2026, with the number of detected signatures jumping from around 21,000 per day to over 1.3 million in a single day, and up to 2.5 million in the following four days.

To combat this threat, Microsoft suggests that developers update email filters to better detect and handle these invisible Unicode tags, which remain a major challenge in modern email cybersecurity.

Written by urgent.news from The Indian Express's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at indianexpress.com →

More in Tech

Exposed Buckets: How S3, GCS, and Azure Blob Are Passively Discovered and Exploited

Before running a single scanner, a researcher opens bucket-stream, connects to certstream, and within minutes has a list of S3 buckets derived from the target company's subdomains.

  • Attackers use CT logs to identify naming patterns and generate bucket names.
  • Specialized scanners confirm existence of sensitive files without triggering alerts.
  • Passive discovery phase leaves no traceable evidence, leading to undetected breaches.

Enabling Karpenter on EKS with Terraform: What It Is, Why It's Worth It, and How to Set It Up

Karpenter replaces the old "guess an instance type, set a min/max, wait for Cluster Autoscaler" model with something simpler: watch for pods that can't schedule, and launch exactly the EC2 capacity…

  • Karpenter replaces EC2 instance management in EKS by launching exact capacity needed.
  • Benefits include right-sized capacity, faster scaling, and Spot instance use.
  • Terraform setup requires IAM roles for Karpenter controller and nodes.

Email Header Analysis: What SMTP Metadata Reveals About Infrastructure and Identity

The email your team flagged as probable phishing contains the attacker's entire infrastructure in 30 lines of plain text. Most analysts check 2 things: SPF pass/fail and the From address.

  • Received chain provides forensic anchor with relay hops, server specs, protocol, and timestamp
  • SLOW#TEMPEST campaign routed Cobalt Strike payloads through Shenzhen Tencent Cloud infrastructure
  • SPF failures pinpoint unauthorized sending IPs for immediate threat intelligence cross-referencing

More from Sunday 6 September →