ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft details high-volume phishing campaign using ASCII smuggling (Unicode tag chars) for filter evasion, peaking at 2.3M messages.
Microsoft researchers observed a high-volume finance-themed phishing campaign using invisible Unicode tag characters (U+E0000–U+E007F), a technique known from AI prompt injection research as ASCII smuggling, to split lure words like 'funding' and evade email filters. Telemetry from Microsoft Defender for Office 365 showed signature hits jump from roughly 21,000 messages on February 8, 2026 to more than 1.3 million on February 9, peaking above 2.3 million on February 11, with elevated weekday activity lasting approximately three months. The discovery emerged from prompt injection protection research, showing AI-era evasion techniques crossing into traditional phishing. Most messages were flagged by layered Defender protections rather than a single Unicode-specific signal.
Chrome's anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome now auto-revokes web push notification permissions, blocking over 7 billion unwanted and abusive notifications daily on Android.
Google announced anti-abuse measures in Chrome that automatically revoke notification permissions for inactive websites and sites Safe Browsing flags for abusive or deceptive notification practices, with users able to restore permissions via Safety Hub. The protections combine Chrome Security, Firebase Cloud Messaging, and Safe Browsing behavioral detection of coordinated abusive networks, and blocked more than 7 billion unwanted notifications per day on Android in Q1. Google also limits abusive domains to 1,000 push messages per minute via FCM and redesigned Android prompts with one-tap unsubscribe.