< Back to situation

[REVISION HISTORY]

Email phishing evasion and security evolution

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-23 04:31 UTC → 2026-09-25 13:57 UTC · added removed

Email phishing evasion techniques and security evolution

Cybersecurity researchers have identified evolving phishing tactics designed to bypass AI-driven email security systems. One method, known as ‘text salting’, involves inserting large amounts of random, harmless text into emails to dilute suspicious keywords. Attackers hide this extra text by using zero-sized fonts, shrinking display windows, or shifting text off-screen to ensure the recipient only sees the fraudulent content. Further developments include ‘ASCII smuggling’, a technique where invisible Unicode characters are used to break up suspicious words. This method allows malicious messages to appear normal to human readers while disrupting the ability of automated filters and machine learning systems to recognize them. Experts suggest that while detection tools Threat actors are important, technical configurations also increasingly utilizing exotic file formats, such as strict ISO disk images, to bypass endpoint detection and response (EDR) and email protection solutions. These files can be mounted natively by operating systems, avoiding the need for suspicious user actions like decompression. To counter these threats, security standards like SPF, DKIM, and DMARC are critical. As of May 2026, DMARC has become an official IETF standard (RFC 9989), though effective protection requires implementing quarantine or rejection policies rather than mere observation. Additional protocols such as MTA-STS and DANE are essential preventative measures against these evasion techniques. also used to enforce transport encryption. In response to AI-generated attacks and complex SaaS ecosystems, new intelligence platforms are being launched to provide unified visibility and governance across evolving email infrastructures.

Versions

  1. 2026-09-25 13:57 UTC Email phishing evasion and security evolution
  2. 2026-09-23 04:31 UTC Email phishing evasion techniques

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.