SecurityWeek’s roundup covers a wide range of cybersecurity developments, from phishing evasion using invisible Unicode and an actively exploited WordPress Super Forms flaw to new US sanctions and a bounty targeting Iranian cyber official Amir Yaryab. It also highlights consent phishing, SIM swapping, cybercrime infrastructure, InjectEave side-channel attacks, and scrutiny of Anthropic’s Project Glasswing findings. #Microsoft #WordPress #SuperForms #AmirYaryab #CISA #FBI #QTFY #ATT #SergeiAnatolyevichFilimonov #InjectEave #Anthropic #ProjectGlasswing
Keypoints
- Microsoft says invisible Unicode tag characters are being used to evade phishing filters.
- Attackers are exploiting CVE-2026-14894 in the WordPress Super Forms plugin.
- The US placed a $10 million bounty on Iranian cyber official Amir Yaryab.
- The FBI warned about OAuth consent phishing used to gain persistent account access.
- Researchers showed InjectEave side-channel attacks can leak audio and device state.