/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says email spammers are adopting ASCII smuggling, an AI prompt injection tactic used to hide malicious instructions, to evade email platform filters

A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters …

Ars Technica Dan Goodin

Context & Ripple Effects

The technique crosses a boundary between AI-agent security and a far older email-security problem. In 2020, researchers identified email-protocol evasion exploits that could disguise spear-phishing, establishing that attackers target how mail systems interpret content rather than only what recipients see.

The July 2026 work on using prompt injections to disrupt attackers’ LLMs also showed that prompt-layer tactics have become a security control and an attack surface. Microsoft’s warning indicates that one such concealment method is being applied to email filtering.

First-order effects

  • Email platforms face an evasion path in which malicious instructions can be concealed from filters while remaining usable by the intended processing chain.
  • Spammers gain a way to reuse an AI-agent prompt-injection technique against conventional email defenses, widening the technique’s target market beyond AI systems.

Second-order effects

  • Microsoft and email-security vendors must test filtering against encoded or non-visible content representations, rather than relying solely on the text a recipient or a basic scanner renders.
  • Organizations deploying AI-assisted mail analysis inherit a shared detection problem: the same concealed content can target filtering workflows and AI-agent instruction handling.

Third-order effects

  • If attackers continue to transfer prompt-layer concealment techniques into email, security products will need to treat content interpretation itself as an enforcement surface across both AI and legacy communications systems.

The trend: AI security techniques are becoming general-purpose evasion tools as attackers apply prompt-layer concealment to established channels such as email.

Discussion

  • r/technology r on reddit
    Once popular for attacking AI, ASCII smuggling is embraced by spammers |  A once-overlooked block of unicode that's invisible to humans is gaining ever wider use.