Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

Cybersecurity News tidbits

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

Here are this week’s highlights: 

Invisible Unicode slips past phishing filters

Microsoft says attackers are using invisible Unicode tag characters, a technique associated with AI prompt injection (ASCII Smuggling), to evade phishing detection. In a campaign tracked from February through June, the characters were inserted into financial lure terms such as “funding,” generating as many as 2.37 million messages per day and potentially disrupting ML- and NLP-based filtering.

Advertisement. Scroll to continue reading.

WordPress Super Forms flaw under attack

Attackers are exploiting CVE-2026-14894, a critical flaw in the WordPress Super Forms plugin that allows unauthenticated arbitrary file uploads. Exploitation can be used to upload and execute PHP webshells, potentially giving attackers complete control of affected sites. Users are advised to update to version 6.3.314.

US puts $10 million bounty on Iranian cyber official

The US is offering up to $10 million for information leading to the identification or location of Amir Yaryab, an IRGC-CEC official who leads its Cyber Operations Command. US authorities say groups under his direction have targeted critical infrastructure across sectors including defense, energy, financial services, telecommunications, shipping and travel, while affiliated groups such as CyberAv3ngers have used malware against civilian infrastructure worldwide.

CISA updates insider threat playbook

CISA has released an updated insider threat guide covering measures to mitigate both physical and cyber threats posed by insiders, addressing aspects such as remote work and AI advancements. The guide is designed to help organizations develop or improve their insider threat program. 

FBI warns of consent phishing 

The FBI is warning that threat actors are using OAuth consent phishing to gain persistent access to victims’ accounts without stealing their passwords. Attackers impersonate trusted figures and direct targets to malicious applications that request legitimate-looking permissions, allowing them to access email, files and other data. 

Deep ties between Chinese hacking group QTFY and military contractors

A new analysis from Natto Thoughts expands on a joint US advisory linking China-based hacking group QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), highlighting ties involving ELEX and Nanjing Lexbell Information Technology. The analysis says ELEX’s historical client lists included MSS, Ministry of Public Security and PLA-affiliated entities, while Lexbell has military-focused products, PLA-linked leadership and contracts with the National University of Defense Technology.

Ex-AT&T employee sentenced to prison for SIM swapping

Former AT&T employee Kenneth Carter was sentenced to 16 months in prison for using his access to perform SIM swaps that helped criminals take over customers’ bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap.

Russian accused of running cybercrime infrastructure

Russian national Sergei Anatolyevich Filimonov was extradited from Georgia and arraigned in the US over an alleged credential-harvesting and bank fraud operation targeting US banking customers. Prosecutors say fake financial websites and sponsored search results directed victims to phishing sites, while infrastructure allegedly maintained by Filimonov stored more than 5,000 stolen credentials and supported attempts to steal millions of dollars.

InjectEave attack turns devices into eavesdropping targets

Researchers demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog information. Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices.

Glasswing findings face a reality check

VulnCheck’s review of Anthropic’s Project Glasswing ledger found that only 202 of 26,153 claimed findings had been fixed after nearly five months, while 245 had been withdrawn. It also found a significant gap between Claude’s severity assessments and those of maintainers: Claude rated 91.5% of findings with available ratings as high or critical, compared with 51.3% from maintainers.

Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.