
Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails
THE SO WHAT
Prompt-injection style Unicode tricks leaking into email phishing means your existing filters and user training are already behind. Security teams should update detection rules for control characters and test how their own AI email summarizers handle adversarial Unicode this week.
READ THE SOURCE
MORE FROM THE WIRE
Deep & Emerging TechStop buying security tools: start buying a system
Security is converging toward continuous, integrated systems rather than point tools with pretty dashboards. CISOs should be rationalizing vendors around data flow, validation, and response automation, not just “consolidation” for its own sake.
Deep & Emerging TechCyber confidence must be tested, never assumed
Purple teaming is moving from “nice-to-have exercise” to the only credible way to validate that your controls work against real attackers. If your board is hearing cyber risk updates without red/blue test results, they’re getting a theory, not a status.
Deep & Emerging Tech'It's extremely creepy': LG TVs collect far more data on you than you'd expect, says new report, including logging microphone audio while on standby and detecting your wireless devices including phones and smartwatches — and users are furious
Smart TVs quietly acting as network sensors and microphones turn every living room and office into a data collection surface. Enterprises should treat consumer-grade displays on corporate networks as untrusted endpoints and segment accordingly.
Deep & Emerging TechRansomware hackers dump 1.4 million stolen records from German government
A 1.4 million-record dump from a government system is another reminder that state-grade targets are not uniquely vulnerable—any large data holder is in scope. If you manage citizen or customer identity data, assume breach and invest in blast-radius reduction, not just perimeter hardening.