SECURITYWEEK’S round-up this week touches a breadth of emerging techniques and enforcement actions shaping the cyber threat landscape. Notably, attackers are experimenting with invisible Unicode tag characters to evade phishing filters, a method linked to AI prompt injection that has driven up to 2.37 million messages per day in a February–June campaign.
While the technique’s reach is broad, specific operational details remain limited, underscoring the need for robust, multi-layered detection beyond surface text claims.
On the software side, WordPress users are being urged to patch CVE-2026-14894, a critical flaw in the Super Forms plugin that allows unauthenticated file uploads and potential execution of PHP webshells; the advised fix is to update to version 6.3.314. In parallel, a former AT&T staff member received a prison sentence for facilitating SIM swaps that helped criminals drain bank accounts, with several victims’ losses and typical payoffs cited for context.
The report also highlights InjectEave, a new class of electromagnetic side-channel attacks that can extract private audio or appliance states from 11 tested devices without tampering with hardware.
Evidence and responses are tempered across items: VulnCheck’s Glasswing review questions the solidity of Anthropic’s findings and severity assessments, while US authorities offer up to $10 million for information locating Amir Yaryab, a figure linked to IRGC cyber operations. Taken together, the notes emphasise practical risk management, timely patching, and careful interpretation of advanced attack demonstrations amid continuing geopolitical cyber activity.