microsoft tried to build a way to stop
prompt injection but ended up catching an entire campaign instead. attackers were using
invisible text to trick how machines parse data, which is pretty wild.
it turns out the detector was too good for its own intended purpose>they caught a phishing ring by accidentdoes anyone else think this means we're abt to see
even weirder bypass techniques?
article:
https://thenewstack.io/unicode-ascii-smuggling-ai-pipelines/