Cybercriminals exploit invisible Unicode and critical WordPress flaw amid rising geopolitical and insider threats

Cybercriminals are deploying advanced techniques such as invisible Unicode characters in phishing campaigns, while critical WordPress plugin flaws and geopolitical tensions highlight escalating cyber threats across sectors.

Microsoft has warned that phishing crews are adopting invisible Unicode characters to slip past automated detection, a technique first associated with AI prompt injection and now being used at scale in finance-themed lures. The company said the campaign relied on deprecated Unicode tag characters that remain visually hidden while altering the underlying text, allowing messages to evade keyword and model-based filtering. Activity rose sharply from 9 February and continued on weekdays for months, with some campaigns reaching as many as 2.37 million messages a day. According to IT Pro, the messages were sent from hundreds of disposable domains and routed through the legitimate marketing platform ActiveCampaign.

At the same time, WordPress site owners are being urged to patch a critical flaw in the Super Forms plugin, which allows unauthorised file uploads and can lead to remote code execution. Security researchers have linked CVE-2026-14894 to active exploitation, with attacks capable of planting PHP web shells and taking full control of affected sites. Wordfence said the weakness is one of two severe plugin issues affecting millions of WordPress installations, while the patch for Super Forms arrived in version 6.3.314. The Hacker Wire said the flaw affected all versions up to and including 6.3.313.

The week’s cybercrime notices also included a US bounty offer of up to $10 million for information on Amir Yaryab, an official linked to the Islamic Revolutionary Guard Corps Cyber Electronic Command. US authorities say groups under his direction have targeted critical infrastructure across defence, energy, financial services, telecommunications, shipping and travel, while associated crews such as CyberAv3ngers have deployed malware against civilian systems worldwide. In a separate warning, the FBI said attackers are increasingly abusing OAuth consent prompts to win persistent access to accounts without stealing passwords, instead tricking victims into granting legitimate-looking permissions to malicious applications.

CISA, meanwhile, has updated its insider-threat playbook to reflect newer workplace realities, including remote work and the growing use of AI tools. The guidance is intended to help organisations strengthen programmes that address both physical and cyber risks from insiders. The agency said the revised material is meant as a practical framework for organisations building or refining their internal monitoring and response controls.

Researchers also drew a sharper picture of links between a China-based hacking group and companies with military connections. Natto Thoughts expanded on a joint US advisory tying the group known as QTFY to Nanjing Xinjiuwei Network Technology, while also pointing to ties involving ELEX and Nanjing Lexbell Information Technology. The analysis said ELEX’s historical client lists included the Ministry of State Security, the Ministry of Public Security and PLA-affiliated bodies, while Lexbell has marketed military-focused products, named PLA-linked leadership and won contracts with the National University of Defense Technology.

On the criminal-law front, former AT&T employee Kenneth Carter was sentenced to 16 months in prison after admitting that he used internal access to carry out SIM swaps that helped criminals seize customers’ bank accounts. Prosecutors said three victims faced intended losses of nearly $600,000, and that Carter typically received $1,000 to $2,000 per fraudulent swap. Separately, Russian national Sergei Anatolyevich Filimonov was extradited from Georgia and arraigned in the US over an alleged credential-harvesting and bank-fraud network that prosecutors say used fake financial websites and search advertising to push victims towards phishing pages. Authorities say the infrastructure allegedly held more than 5,000 stolen credentials and supported attempts to steal millions of dollars.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.