In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Cybersecurity News Roundup: Attackers Evade Detection with Invisible Unicode Characters and Exploit Critical WordPress Flaw

A recent wave of attacks has seen cybercriminals leveraging cutting-edge techniques to evade detection and compromise sensitive systems. One such tactic involves using invisible Unicode characters, which have been inserted into phishing lures to bypass filtering mechanisms. This campaign, tracked from February through June, generated an astonishing 2.37 million messages per day, potentially disrupting machine learning (ML) and natural language processing (NLP)-based filtering.

The use of invisible Unicode characters is associated with AI prompt injection, also known as ASCII Smuggling. By inserting these characters into seemingly innocuous terms like “funding,” attackers can create lures that evade traditional phishing detection methods. The implications are significant, as this technique could allow malicious actors to breach even the most secure systems undetected.

In another concerning development, a critical flaw in the WordPress Super Forms plugin has been exploited by attackers. CVE-2026-14894 allows unauthenticated arbitrary file uploads, enabling cybercriminals to upload and execute PHP webshells on affected sites. Users are advised to update to version 6.3.314 as soon as possible to prevent potential compromise.

Meanwhile, the US government is offering a $10 million bounty for information leading to the identification or location of Amir Yaryab, an Iranian cyber official who leads the IRGC-CEC’s Cyber Operations Command. Groups under his direction have targeted critical infrastructure across various sectors, including defense, energy, and finance, while affiliated groups like CyberAv3ngers have used malware against civilian infrastructure worldwide.

In related news, CISA has released an updated insider threat guide covering measures to mitigate both physical and cyber threats posed by insiders. The guide addresses aspects such as remote work and AI advancements, providing organizations with valuable insights on how to develop or improve their insider threat programs.

Another alarming trend involves the use of OAuth consent phishing by threat actors. By impersonating trusted figures and directing targets to malicious applications that request legitimate-looking permissions, attackers can gain persistent access to victims’ accounts without stealing their passwords. The FBI has issued a warning regarding this tactic, emphasizing its potential for devastating consequences.

A new analysis from Natto Thoughts expands on the ties between Chinese hacking group QTFY and military contractors. The joint US advisory highlights connections involving ELEX and Nanjing Lexbell Information Technology, with implications that raise concerns about national security.

In a separate case, a former AT&T employee was sentenced to 16 months in prison for using his access to perform SIM swaps that helped criminals take over customers’ bank accounts. Three victims suffered intended losses of nearly $600,000, highlighting the importance of robust cybersecurity measures within organizations.

Finally, researchers have demonstrated a new class of electromagnetic side-channel attacks called InjectEave, which can turn devices into eavesdropping targets without physical access or modification. This attack exploits hardware nonlinearities induced by an external RF signal, potentially allowing attackers to recover private audio or determine appliance states.

As the cybersecurity landscape continues to evolve, it is essential for individuals and organizations to stay informed about emerging threats and vulnerabilities. By understanding these complex issues and taking proactive measures to protect sensitive systems, we can mitigate the risk of devastating cyberattacks.


Source: SecurityWeek — 2026-09-11