When Your Email Filter Can't See the Threat
Every email security gateway runs on the same assumption: if it can parse the message, it can judge the message. That assumption has a crack in it, and attackers just drove a truck through.
Vade, a proofpoint company, tracked a phishing campaign they call Laurium that embeds phishing URLs inside Unicode "tag block" code points. These aren't homoglyphs dressed up to look like familiar letters. They're characters that render as nothing at all — invisible placeholders that carry hidden text payloads. The link the user sees? Totally benign. The link the browser actually visits? Completely different.
What makes this genuinely ugly is that it doesn't require a zero-day or a novel malware family. It's a protocol-level trick that exploits the gap between how email scanners parse messages and how browsers render them. The filters see clean text. The browser sees a URL. The user clicks. Game over.
How Invisible Unicode Characters Bypass Email Security
Unicode's tag block sits in a reserved range that the Unicode Consortium designed for language-tag metadata — the kind of thing used to flag the natural language of a document. In practice, almost nothing in normal email traffic needs those code points. They're supposed to be empty space in any real message.
Attackers exploited that. They stuffed a phishing URL into the tag block sequence. Most email security filters don't normalize these characters because they weren't designed to. The scanner sees the visible part of the string, finds no suspicious domain, scores it clean, and delivers it. The browser, on the other hand, processes those invisible code points as a hidden URL component and navigates there when the user clicks.
Vade called this the first phishing campaign leveraging ASCII smuggling that they'd observed at scale. The technique works because it doesn't try to fool the filter with clever obfuscation. It simply hides from it.
The elegance — and the danger — here is that it's trivially easy to implement. You don't need a C2 infrastructure or polymorphic code. You need a text editor that lets you insert code points.
AI Cybersecurity Threats Extend Into the Prompt
This is where the story stops being about email and starts being about something bigger. ASCII smuggling isn't just an anti-spam bypass. It's an AI attack vector.
Security researcher Johann Rehberger demonstrated in 2024 that the same invisible-character trick works against large language models. He showed how Microsoft 365 Copilot could be fed a payload containing hidden Unicode that the model would process internally but never render to the user. The model "sees" instructions the human never sees. Rehberger called ASCII smuggling "a novel technique that uses special Unicode characters that mirror ASCII but are actually not visible in the user interface."
The exploit chain he documented required several steps chained together: trigger a prompt injection through a malicious document shared in chat, use that injected instruction to tell Copilot to search the user's emails and files, then exfiltrate results encoded inside those same invisible tag block characters embedded in a clickable link. The user sees a normal hyperlink. The click transmits stolen data.
Microsoft patched this in August 2024. Google, when researchers reported the identical attack against Gemini, said they had no plans to address it.
What Is AI in Cyber Security? The Honest Answer
Ask ten people what AI in cyber security means and you'll get a marketing brochure. The reality is messier.
AI in cyber security is pattern matching at scale — anomaly detection, behavioral analysis, reputation scoring, triage automation. It's the system that correlates your 4,000 daily alerts down to the twelve that matter. It's also the system attackers now poison, manipulate, and weaponize.
The question of how AI is used in cybersecurity has two halves. On the defensive side, it powers everything from email filtering to endpoint detection. On the offensive side — and this is the part the vendor decks skip — it creates new attack surface that didn't exist before. An LLM that summarizes your email is an LLM that can be told to steal from you. A Copilot that retrieves documents is a Copilot that can be told to encode results into an invisible URL.
That's the core paradox. The AI systems designed to help defenders are the same systems attackers inject into. AI cybersecurity threats in 2026 aren't hypothetical. They're operational, active, and in some cases vendor-refused-to-fix.
The 2026 Defense Gap
Microsoft's Digital Defense Report warned that attackers adopt new tools faster than defenders integrate them. The Laurium campaign and the Copilot/Gemini incidents prove the point at both ends of the pipeline.
On the email side, the attack bypasses traditional spam filters and reputation-based scoring. These systems have never seen tag block characters in phishing before at scale. Detection rules don't exist for payloads that render invisible. Microsoft Security did ship a detection capability for ASCII smuggling in Microsoft Defender for Office 365, but broad rollout against commodity phishing campaigns takes time, and Vade's discovery suggests attackers moved first.
On the AI side, the attack bypasses model-level guardrails entirely. The prompt isn't adversarial at the semantic level. It's adversarial at the encoding level. Guardrails that filter for jailbreak phrasing or instruction override text don't catch this because the instruction isn't phrased adversarially — it's encoded invisibly.
This matters for broader prompt injection defense strategies too. Organizations that built their AI security posture around input filtering — block the injection, block the attack — need to add an encoding normalization layer in front of any LLM that ingests user-adjacent content.
What Defenders Should Do Now
There's no single fix. But there are clear moves that close most of this gap:
Normalize inputs before they reach a scanner or a model. Tag block code points, zero-width joiners, and other invisible characters should be stripped or flagged at the email gateway and again at the LLM ingestion boundary. Microsoft's Azure ADDS team added tag block detection. Other email platforms should follow.
Treat LLM output as untrusted. If Copilot or Gemini renders a clickable link, that link should be validated against a URL allowlist before the user clicks. This adds friction, yes. But it's the only reliable check against data exfiltration encoded in URLs.
Assume model providers won't save you. Google's refusal to fix the Gemini ASCII smuggling vector is a signal. If your AI security posture depends on a vendor patching an encoding-level flaw, you have no posture. You have a hope.
Watch for copycat campaigns. Vade caught Laurium at scale. The technique is trivially reproducible. Expect it in credential-harvesting kits and BEC toolkits within months, not years.
The 2026 threat landscape isn't just about AI making attacks faster or more convincing. It's about AI systems being structurally vulnerable to inputs that humans can't see. That's a harder problem to solve than a convincing deepfake or a polymorphic macro. It goes down to the encoding layer, and nobody built defenses there yet.