Analysis · curated 5 Sep 2026
Microsoft built a prompt injection detector. Then it caught a phishing campaign instead.
First reported thenewstack.io
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Unicode and ASCII smuggling lets attackers hide prompt-injection or data-exfiltration payloads in text that reaches LLMs, so defenders need detection capable of surfacing such hidden content in AI pipelines.
The New Stack reports that Microsoft built a prompt injection detector aimed at AI pipelines and, in the course of hunting for Unicode/ASCII smuggling attacks, the tooling surfaced a phishing campaign instead. The piece discusses how invisible Unicode/ASCII smuggling can be used to hide malicious instructions inside text fed to LLM-based AI pipelines.