Attackers conceal phishing lures using invisible Unicode characters

2026-09-06T19:23:22Zb46e9402fc0a9484c9303de5a1ea1851077cde81193b349a94cf0493d41b7bd3
CVE-2026-19490ASCII smugglingArubaOS-CXChrome V8Citrix NetScalerClickFixCrowdStrike FalconMicrosoft outageTerraform modulesUnicode evasionactive exploitationblockchain malware deliverycredential theftdata breachhealthcareidentity datapasskeysphishingprivilege escalationremote code executionsupply-chain compromisezero-day

What happened

BleepingComputer security feed covering active exploitation of critical vulnerabilities, zero-days, phishing evasion, ClickFix malware delivery, software supply-chain compromise, authentication risks, major data breaches, and security-related service outages. The most urgent items include an in-the-wild Citrix NetScaler authentication bypass (CVE-2026-19490), an actively exploited Chrome V8 zero-day, a CrowdStrike Falcon privilege-escalation zero-day, and critical ArubaOS-CX remote code execution remediation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b46e9402fc0a9484c9303de5a1ea1851077cde81193b349a94cf0493d41b7bd3
Enrichment time
2026-09-06T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers conceal phishing lures using invisible Unicode characters · Baitaphish