1M+ Emails Use Hidden Text to Dupe AI Security Filters
Over one million phishing emails reportedly bypass AI-driven filters by injecting invisible characters — a technique that exploits how LLMs tokenise text and could hit any organisation relying solely on AI-based email defence.
Summary written by editorial AI · Source link below
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
Editorial Analysis
Enterprises investing heavily in AI-based email security may carry unrecognised residual risk; text-salting shows that adversarial evasion of LLM classifiers is practical and already at scale.
Audit your email gateway's handling of Unicode normalisation and supplement AI-based filtering with rule-based checks for invisible character injection.
AI email filters can be bypassed at scale using simple text manipulation, highlighting the need for layered defences beyond AI alone.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul