In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Invisible Unicode evades phishing, US bounty on Iranian cyber official, and QTFY group ties to China's military.
Summary
This week's security news roundup covers several key developments. Attackers are using invisible Unicode characters to bypass AI-powered phishing filters, with millions of messages sent daily. The US has placed a $10 million bounty on an Iranian cyber official, citing his role in targeting critical infrastructure. Additionally, new analysis reveals deep ties between the Chinese hacking group QTFY and military contractors.
Full text
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment. Here are this week’s highlights: Invisible Unicode slips past phishing filters Microsoft says attackers are using invisible Unicode tag characters, a technique associated with AI prompt injection (ASCII Smuggling), to evade phishing detection. In a campaign tracked from February through June, the characters were inserted into financial lure terms such as “funding,” generating as many as 2.37 million messages per day and potentially disrupting ML- and NLP-based filtering. Advertisement. Scroll to continue reading. WordPress Super Forms flaw under attack Attackers are exploiting CVE-2026-14894, a critical flaw in the WordPress Super Forms plugin that allows unauthenticated arbitrary file uploads. Exploitation can be used to upload and execute PHP webshells, potentially giving attackers complete control of affected sites. Users are advised to update to version 6.3.314. US puts $10 million bounty on Iranian cyber official The US is offering up to $10 million for information leading to the identification or location of Amir Yaryab, an IRGC-CEC official who leads its Cyber Operations Command. US authorities say groups under his direction have targeted critical infrastructure across sectors including defense, energy, financial services, telecommunications, shipping and travel, while affiliated groups such as CyberAv3ngers have used malware against civilian infrastructure worldwide. CISA updates insider threat playbook CISA has released an updated insider threat guide covering measures to mitigate both physical and cyber threats posed by insiders, addressing aspects such as remote work and AI advancements. The guide is designed to help organizations develop or improve their insider threat program. FBI warns of consent phishing The FBI is warning that threat actors are using OAuth consent phishing to gain persistent access to victims’ accounts without stealing their passwords. Attackers impersonate trusted figures and direct targets to malicious applications that request legitimate-looking permissions, allowing them to access email, files and other data. Deep ties between Chinese hacking group QTFY and military contractors A new analysis from Natto Thoughts expands on a joint US advisory linking China-based hacking group QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), highlighting ties involving ELEX and Nanjing Lexbell Information Technology. The analysis says ELEX’s historical client lists included MSS, Ministry of Public Security and PLA-affiliated entities, while Lexbell has military-focused products, PLA-linked leadership and contracts with the National University of Defense Technology. Ex-AT&T employee sentenced to prison for SIM swapping Former AT&T employee Kenneth Carter was sentenced to 16 months in prison for using his access to perform SIM swaps that helped criminals take over customers’ bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap. Russian accused of running cybercrime infrastructure Russian national Sergei Anatolyevich Filimonov was extradited from Georgia and arraigned in the US over an alleged credential-harvesting and bank fraud operation targeting US banking customers. Prosecutors say fake financial websites and sponsored search results directed victims to phishing sites, while infrastructure allegedly maintained by Filimonov stored more than 5,000 stolen credentials and supported attempts to steal millions of dollars. InjectEave attack turns devices into eavesdropping targets Researchers demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog information. Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices. Glasswing findings face a reality check VulnCheck’s review of Anthropic’s Project Glasswing ledger found that only 202 of 26,153 claimed findings had been fixed after nearly five months, while 245 had been withdrawn. It also found a significant gap between Claude’s severity assessments and those of maintainers: Claude rated 91.5% of findings with available ratings as high or critical, compared with 51.3% from maintainers. Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation Written By SecurityWeek News Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from SecurityWeek News Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint RemediationIn Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B ValuationPalo Alto Networks Acquires AI Agent Platform ConsoleIn Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker SanctionsOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugVirtual Event Today: CodeSecCon – Secure Your Code and Applications Latest News Trezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonCheck Point Patches Critical VPN VulnerabilitiesKiteworks Acquires Bonfy.AI to Fill the AI Gap in Data GovernanceSurfshark Systems Targeted by HackersAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionPaperCut Flaws Exploited in AI-Powered AttacksMandiant Founder Kevin Mandia Joins Amazon Board Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authenticatio
Indicators of Compromise
- cve — CVE-2026-14894
- malware — InjectEave
- malware — ASCII Smuggling