Follow the latest coverage, related explainers and connected technology stories.
Microsoft researchers identified a widespread phishing campaign that used invisible Unicode characters to split finance-related words and evade email filters. The campaign peaked at 2.37 million messages per day, although Microsoft Defender for Office 365 blocked more than 99% of them based on other signals.
Microsoft researchers identified a widespread financial phishing campaign that used invisible Unicode characters from the Tags block to split words such as funding before messages were analyzed, repurposing a technique known from prompt-injection attacks against artificial intelligence models. Related detections rose from approximately 21,000 messages to more than 1.3 million messages on February 9, 2026.
Microsoft is investigating a defect in Defender for Office 365 Safe Links that caused some legitimate Google Search links to be classified as malicious and blocked from opening. IT administrators may receive incident-related alerts in Microsoft Defender and Microsoft Sentinel, with no impact scope or remediation timeline announced.