In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
This week’s cybersecurity news highlights a range of threats and vulnerabilities. Attackers are leveraging invisible Unicode characters to bypass phishing filters, exploiting a WordPress plugin for remote code execution, and using OAuth consent phishing to steal user accounts. Simultaneously, a Russian national is facing charges for credential harvesting, and researchers have demonstrated a new type of electromagnetic side-channel attack. The US is also offering a $10 million reward for information leading to the capture of an Iranian cyber official.
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
What happened
Microsoft is reporting that attackers are utilizing invisible Unicode tag characters to evade phishing detection. The campaign, running from February through June, involved inserting these characters into financial lure terms, generating up to 2.37 million messages daily, and potentially disrupting ML- and NLP-based filtering.
Attackers are exploiting CVE-2026-14894, a critical flaw in the WordPress Super Forms plugin, allowing unauthenticated arbitrary file uploads. This vulnerability enables the upload and execution of PHP webshells, potentially granting attackers complete control over affected websites. Users are advised to update to version 6.3.314.
The US Department of Justice is offering a $10 million reward for information leading to the identification or location of Amir Yaryab, an IRGC-CEC official who leads its Cyber Operations Command. Groups under his direction have targeted critical infrastructure across sectors including defense, energy, financial services, telecommunications, shipping and travel, with affiliated groups such as CyberAv3ngers using malware against civilian infrastructure worldwide.
The CISA has released an updated insider threat guide, addressing measures to mitigate both physical and cyber threats posed by insiders, particularly in light of remote work and AI advancements.
The FBI is warning about consent phishing, where threat actors impersonate trusted figures and direct targets to malicious applications that request legitimate-looking permissions, allowing them to access email, files and other data.
A new analysis from Natto Thoughts expands on a joint US advisory linking China-based hacking group QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), highlighting ties involving ELEX and Nanjing Lexbell Information Technology. ELEX’s historical client lists included MSS, Ministry of Public Security and PLA-affiliated entities, while Lexbell has military-focused products, PLA-linked leadership and contracts with the National University of Defense Technology.
Former AT&T employee Kenneth Carter was sentenced to 16 months in prison for using his access to perform SIM swaps that helped criminals take over customers’ bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap.
Russian national Sergei Anatolyevich Filimonov was extradited from Georgia and arraigned in the US over an alleged credential-harvesting and bank fraud operation targeting US banking customers. Prosecutors say fake financial websites and sponsored search results directed victims to phishing sites, while infrastructure allegedly maintained by Filimonov stored more than 5,000 stolen credentials and supported attempts to steal millions of dollars.
Researchers demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog information. Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices.
VulnCheck’s review of Anthropic’s Project Glasswing ledger found that only 202 of 26,153 claimed findings had been fixed after nearly five months, while 245 had been withdrawn. It also found a significant gap between Claude’s severity assessments and those of maintainers: Claude rated 91.5% of findings with available ratings as high or critical, compared with 51.3% from maintainers.