View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Phishing Wave Sends Millions of Emails Using Invisible Unicode

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Phishing Wave Sends Millions of Emails Using Invisible Unicode to Evade Filters
    Microsoft has warned of a high-volume phishing campaign that uses invisible Unicode tag characters to split financial lure words and bypass email filters.

    • Affects email recipients and organizations whose mail filters rely on keyword, signature, or regex matching; lures mimic business loan, line-of-credit, and advance-funding offers.
    • The campaign, known as ASCII smuggling, abuses the deprecated Unicode Tags block (U+E0000 to U+E007F), inserting invisible characters inside financial keywords so 'funding' becomes 'funding', rendering it invisible to literal string detectors while reading normally to recipients.
    • Attacks first emerged in early February 2026 and ran at high volume for roughly three months before dropping sharply after May 15, 2026, with weekday volumes reaching 1–2.37 million messages and near silence on weekends.
    • Emails were sent from hundreds of disposable finance-themed sender domains (e.g., guardiangrowthfunding[.]com, digitalcapitalboost[.]com, thebusinessloanexpress[.]com) and relayed through ActiveCampaign, routing links via its click-tracking domains acemlnd[.]com and activehosted[.]com to leverage the platform's legitimate IP reputation.
    • Microsoft assesses the activity is tied to a broader campaign that weaponized ActiveCampaign to distribute AI-generated phishing emails targeting Small Business Administration (SBA) loan applicants.
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Linux kernel fix: Tegra gr2d/gr3d register map now initialized before HOST1X client registration (CVE-2026-80883)
    A Linux kernel vulnerability in the NVIDIA Tegra DRM gr2d/gr3d drivers, where userspace could submit jobs before the register map was initialized, has been fixed.

    • Affects the Linux kernel drm/tegra gr2d/gr3d drivers on NVIDIA Tegra SoCs, where host1x_client_register() made the device available to userspace before the address register map was initialized.
    • Userspace could submit a job before the register map was initialized, causing a race condition.
    • Fixed by moving register initialization before HOST1X client registration.
    • Affected versions: any before 6.6.145, 6.12.97, 6.18.40, or 7.1.5; fixes landed in commits 6e22d5ad, 5db37fd7, 40a2a91d, 3055292b, and c4ef5ba1.
      πŸ“„ Source: git.kernel.org Β· πŸ“Ž Coverage: cve.threatint.com Β· πŸ‘ via CVE ThreatInt
  • 8-K Friday: Watch for SEC breach filings under cover of weekend news
    A Mastodon post highlights the practice of companies filing SEC 8-K breach disclosures on Friday nights to minimize PR impact.

    • Applies to public companies required to disclose material breaches via SEC Form 8-K.
    • Friday evening filings are used to avoid the weekday news cycle β€” tracked under the #8kFriday hashtag.
    • No specific company, breach, or CVE was identified in this item.
      πŸ“Ž Coverage: cyberplace.social Β· πŸ‘ via @GossiTheDog@cyberplace.social
  • Missive user asks whether connecting Exa web search via MCP is safe to roll out
    A company using Missive is asking whether connecting Exa web search to its AI assistant via MCP is secure.

    • Applies to companies using Missive for company email, whose built-in AI assistant cannot search the web
    • The user tested connecting Exa through MCP, allowing only web search and disabling agents
    • The integration worked in testing, but the user is unsure whether it is secure enough to roll out company-wide
    • The concern raised is prompt injection risk from letting the assistant query the web
      πŸ“Ž Coverage: reddit.com Β· πŸ‘ via r/cybersecurity
  • πŸ•΅οΈ RESEARCH & DEEP DIVES (ONE-LINERS)

  • IDScan sued over alleged data breach affecting 153 million drivers β€” BleepingComputer

  • In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation β€” SecurityWeek

  • HPE Patches Critical RCE Vulnerabilities in AOS-CX β€” SecurityWeek

  • Using a VM to Contain an AI Agent β€” Schneier on Security

  • Companies Have 6 Months to Prepare for Automated Attacks β€” Dark Reading

  • PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution β€” The Hacker News

  • undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in s... β€” CVE ThreatInt

  • undici vulnerable to response truncation via oversized chunked responses in t... β€” CVE ThreatInt

  • serial: msm: Disable DMA for kernel console UARTIn the Linux kernel, the foll... β€” CVE ThreatInt

  • afs: Fix uncancelled rxrpc OOB message handlerIn the Linux kernel, the follow... β€” CVE ThreatInt

  • ntb: Store original DMA address for future releaseIn the Linux kernel, the fo... β€” CVE ThreatInt

  • crypto: tegra - Return ENOMEM when input buffer allocation fails for ccmIn th... β€” CVE ThreatInt

  • ocfs2: fix buffer head management in ocfs2_read_blocks()In the Linux kernel, ... β€” CVE ThreatInt

  • IB/mlx5: Properly support implicit ODP rereg_mrIn the Linux kernel, the follo... β€” CVE ThreatInt

  • ocfs2: fix circular locking dependency in ocfs2_dio_end_io_writeIn the Linux ... β€” CVE ThreatInt

  • afs: Fix leak of ungot volumeIn the Linux kernel, the following vulnerability... β€” CVE ThreatInt

  • afs: Fix vllist leakIn the Linux kernel, the following vulnerability has been... β€” CVE ThreatInt

  • ring-buffer: Fix event length with forced 8-byte alignmentIn the Linux kernel... β€” CVE ThreatInt

  • ipvs: use parsed transport offset in TCP state lookupIn the Linux kernel, the... β€” CVE ThreatInt

  • arm64: dts: renesas: ironhide: Describe inline ECC carveoutsIn the Linux kern... β€” CVE ThreatInt

  • KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptionsIn the Lin... β€” CVE ThreatInt

  • ALSA: hda/tas2781: Cancel async firmware request at unbindIn the Linux kernel... β€” CVE ThreatInt

  • crypto: xilinx-trng - Remove crypto_rng interfaceIn the Linux kernel, the fol... β€” CVE ThreatInt

  • drm/amdkfd: Validate CRIU-restored IDs before idr_allocIn the Linux kernel, t... β€” CVE ThreatInt

  • ntfs: bound the attribute-list entry in ntfs_read_inode_mount()In the Linux k... β€” CVE ThreatInt

  • OSPAR 2026 report now available with 167 services in scope β€” AWS Security Blog

  • Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally β€” Cyber Security News

  • KEV: CVE-2026-85046 β€” Google Chromium V8 β€” Google Chromium V8 Type Confusion Vulnerability β€” CISA KEV

  • CVE-2026-75430: PowerJob Worker Unauthenticated RCE β€” thehackerwire.com (discovered)

  • FastChat Authentication Bypass Leads to SSRF β€” <https://www.theh

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check