{
  "id": 5726454,
  "title": "Microsoft says email spammers are adopting ASCII smuggling, an AI prompt injection tactic used to hide malicious instructions, to evade email platform filters (Dan Goodin/Ars Technica)",
  "url": "https://urgent.news/2026/09/05/microsoft-says-email-spammers-are-adopting-ascii-smuggling-an-ai",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-05T06:05:26.000Z",
  "source": {
    "name": "Techmeme",
    "slug": "techmeme",
    "url": "https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/"
  },
  "original_language": "en",
  "account": null,
  "summary": "Microsoft has reported that spammers are using a technique called ASCII smuggling to evade email filters. This technique, typically used to hide malicious prompts in AI attacks, involves embedding invisible Unicode characters in emails to conceal malicious instructions. According to Microsoft researchers Noam Kochavi and Sarah Wolstencroft, cited by The Register, ASCII smuggling allows attackers to hide content inside text that appears normal to humans but can be decoded by computers.\n\nThe Register and Ars Technica reports that Microsoft uncovered a massive phishing campaign using this technique, which peaked at over 2.37 million messages in late February and remained elevated over the next three months. The campaign used invisible Unicode tag characters to hide malicious prompts, making it difficult for email filters to detect. As The Register notes, this technique is popular for indirect prompt injection attacks, where an attacker hides instructions for an AI assistant in invisible Unicode characters.\n\nArs Technica provides more details on ASCII smuggling, explaining that it uses a special range of Unicode tags that mimic the American Standard Code for Information Interchange. These tags, such as U+E0041 and U+E0061, encode characters that are readable by computers but almost completely invisible to humans. By expressing malicious prompts in these tags, attackers can hide instructions that are detectable by AI models but not by humans reading the email.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Ars Technica",
        "title": "Once popular for attacking AI, ASCII smuggling is embraced by spammers",
        "url": "https://urgent.news/2026/09/04/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers",
        "published": "2026-09-04T17:18:12.000Z"
      },
      {
        "outlet": "The Register Science",
        "title": "ASCII smuggling isn't just an AI security risk",
        "url": "https://urgent.news/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk",
        "published": "2026-09-04T19:23:25.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}