1M+ Emails Use Hidden Text to Dupe AI Security Filters
Over one million phishing emails reportedly bypass AI-driven filters by injecting invisible characters — a technique that exploits how LLMs tokenise text and could hit any organisation relying solely on AI-based email defence.
Summary written by editorial AI · Source link below
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
Editorial Analysis
Enterprises investing heavily in AI-based email security may carry unrecognised residual risk; text-salting shows that adversarial evasion of LLM classifiers is practical and already at scale.
Audit your email gateway's handling of Unicode normalisation and supplement AI-based filtering with rule-based checks for invisible character injection.
AI email filters can be bypassed at scale using simple text manipulation, highlighting the need for layered defences beyond AI alone.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d