In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.
Here are this week’s highlights:
Invisible Unicode slips past phishing filters
Microsoft says attackers are using invisible Unicode tag characters, a technique associated with AI prompt injection (ASCII Smuggling), to evade phishing detection. In a campaign tracked from February through June, the characters were inserted into financial lure terms such as “funding,” generating as many as 2.37 million messages per day and potentially disrupting ML- and NLP-based filtering.
WordPress Super Forms flaw under attack
Advertisement. Scroll to continue reading.
Attackers are exploiting CVE-2026-14894, a critical flaw in the WordPress Super Forms...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE