Millions of Phishing Emails Hid Their Most Suspicious Words in Plain Sight

Millions of messages a day used invisible Unicode characters to split high-signal finance words. Humans saw “funding.” Some security pipelines saw something else.

Millions of messages a day used invisible Unicode characters to split high-signal finance words. Humans saw “funding.” Some security pipelines saw something else.

Microsoft says a China-focused campaign is rebuilding malicious installers between downloads, making familiar names and file hashes unreliable clues.

A fake verification prompt led to DLL sideloading, Active Directory reconnaissance and a reverse tunnel that turned one Windows endpoint into an internal network pivot.

ShieldBreak is now CVE-2026-69414, a Microsoft Defender elevation-of-privilege vulnerability assessed as exploitation more likely and still awaiting a verifiable fix. This update separates it from RoguePlanet CVE-2026-50656, explains the different CFAPI attack path, conflicting Windows 11 reproduction results, affected-build uncertainty, and the operational controls security teams should use instead of treating patch deployment as proof that exposure is fixed.