An AI hacking trick is now being used to split the word ‘funding’ in spam

https://media.thenextweb.com/2026/08/Microsoft-logo.jpg

For two years, invisible Unicode characters have been the neat trick of AI security research. You hide instructions inside them. A person sees nothing. A language model reads them and does as it is told.

Microsoft has now found somebody using the same characters for something far less clever. They were splitting up the word “funding” in spam.

Noam Kochavi and Sarah Wolstencroft of Microsoft Security Research published the finding in a blog post on Thursday. At its height the campaign pushed millions of messages a weekday.

The block of characters nobody wanted

The technique is called ASCII smuggling. It uses the Unicode Tags block, U+E0000 to U+E007F. That block holds an invisible shadow copy of the printable ASCII characters. U+E0041 mirrors a capital A. U+E0061 mirrors a lowercase one.

Unicode created the block for language tagging, then abandoned the idea. A later plan to use it for regional flags...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more