6 Sept 2026 · BleepingComputer · incident
A phishing campaign peaking at 2.37 million messages a day split finance keywords with invisible characters from the Unicode Tags block, so keyword filters never matched them while readers saw ordinary words.
13 Aug 2026 · 404 Media · incident
A plaintiff hid instructions in 3-point white text throughout a court filing, telling any AI that read it to agree with the filing; the court noticed the extra white space and banned him from electronic filing.
10 Aug 2026 · Decrypt · incident
PromptArmor showed that a PDF uploaded to Atlassian's Rovo assistant could carry an instruction set in transparent colour at one pixel, telling it to gather sensitive data and post it to an attacker's URL — with no approval click and no warning.
2 Aug 2026 · arXiv · research
A benchmark of 29,322 PDFs built from 4,983 real documents, injecting payloads through invisible render mode, tiny fonts, white and low-contrast text and off-page placement — every one of which is a technique we detect.
29 Jul 2026 · The Register · research
A researcher showed that small white text in a Word document could tell Copilot to alter financial figures and copy the same instructions into every document it generated — a worm, disclosed after 144 days without a fix.
16 Jul 2026 · Dark Reading · incident
Over a million phishing emails padded their HTML with filler text hidden three ways at once — zero font size, a container with zero height and width, and overflow pushed off-screen — so filters reading the markup saw harmless words while the reader saw the lure.
27 May 2026 · USENIX Security 2026 · research
Across 196,682 real résumés submitted to a live hiring platform, roughly 1% carried a prompt injection hidden by white-on-white text, 1pt fonts or text placed off the page — and more than 90% of those prompts contained no explicit instruction at all, so a phrase matcher catches under one in ten.
29 Apr 2026 · arXiv · research
A crawl of 1.2 billion URLs across 24.8 million hosts found 15,300 validated injections on 11,700 pages, about 70% of them sitting in parts of the HTML a browser never renders — headers, comments and metadata.
3 Mar 2026 · Unit 42, Palo Alto Networks · research
Twenty-two distinct payload techniques found on real malicious sites — zero font size, elements pushed 9,999 pixels off screen, display:none, attribute cloaking and prompts tucked inside SVG — aimed at everything from ad-review evasion to forced transactions. The SVG case reached us as `clean` until engine 0.263.0.
7 Jan 2026 · PromptArmor · vendor disclosure
A résumé PDF carried an instruction in 1-point white-on-white text with a white image laid over it, and Notion AI built URLs containing salary expectations and candidate feedback, then embedded them as images so the browser sent them to the attacker.