Once popular for attacking AI, ASCII smuggling is embraced by spammers

A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns.

The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a class of AI attack known as prompt injections more stealthy. Malicious instructions embedded in emails or other untrusted content to be processed by an LLM aren’t written in ordinary text. Instead, they’re rendered by a special range of Unicode tags. For example, the tag point U+E0041 mirrors “A,” and U+E0061 mirrors “a.”

No longer just for obscuring prompt injections

The block of 128 tags mimics a portion of the American Standard Code for Information Interchange almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. By expressing the malicious prompts in these tags, LLMs detect the instructions, but people reading the email never see them. There’s much more about ASCII smuggling here.

Read full article

Comments

https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/




Anthropic’s $2 trillion IPO puts powerful external trustees in spotlight

Anthropic’s prospective public-market investors must reckon with an external group of trustees that control the majority of the AI company’s board, as its planned blockbuster initial public offering forces close scrutiny of its experimental governance structure.

The company’s Long-Term Benefit Trust (LTBT) is a small group of advisers created to safeguard the lab’s mission of developing AI for the long-term benefit of humanity, even as commercial pressures intensify.

The trust holds no equity in Anthropic, but has significant influence, with the San Francisco-based company planning to preserve its role after a stock market debut that could value the Claude maker at as much as $2 trillion.

Read full article

Comments

https://arstechnica.com/ai/2026/09/anthropics-2-trillion-ipo-puts-powerful-external-trustees-in-spotlight/




Catch Raises $5 Million for AI Executive Assistant With Guardrails

Catch, an agentic admin assistant for leaders, has raised $5 million to accelerate its purpose to solve executives’ daily pain points.

The funding was co-led by Entrée Capital and Pitango, with participation from Seedcamp and Factorial Capital.

Catch, an AI startup co-founded by Nir Sabato (CEO) and Yoav Ramon (CTO), develops an AI admin assistant – also called Catch – that the developers claim demonstrates AI agents can safely move beyond analysis and reporting toward active decision-making. It is designed to behave like a human executive assistant, and handles sensitive communications, scheduling, and personal data with the same level of care expected from a trusted executive assistant.

The executive user explicitly defines, during the onboarding process, which personal and workspace assets Catch can access. So, for example, if it is granted access to the executive’s inbox, calendar and travel accounts, it will monitor just these. But if it detects a flight booked with no hotel attached, its reasoning capabilities will proactively check rates at the executive’s usual hotel and ask whether to book it.

It is a human-like judgment call, keeping the human executive in the loop to maintain the agent’s boundaries.

Catch can coordinate with the executive’s guests to schedule meetings, book travel, and handle follow ups to correspondence. “Catch works out of the box within minutes of syncing – building a profile of the executive, who they work with, how they like to meet and travel, and starts acting on it over text, email, Slack or phone, with no new tool or UI to learn. Human input is only needed when a decision genuinely requires it,” explain the developers.

Advertisement. Scroll to continue reading.

The product provides an implicit argument for outsourced rather than self-built complex agents. With modern coding agents, executives can build their own agentic admin assistants, but it is questionable whether they can build a secure agent, or the security team can build adequate guardrails to secure the output without impacting the benefits. Outsourced agents could – in fact, should – be delivered ready made with the correct built-in security features.

In this case, the autonomy and security of Catch is constrained by multiple internal guardrails. It runs on a cloud infrastructure with layers of security, encryption, and monitoring to protect user data. It never performs actions outside the granted permissions, which can be amended at any time. It includes the executive human in the loop, similar to a human assistant saying to his boss, “You’re going to Memphis next week, should I book a room at this hotel for you?”

Catch uses single sign-on for authentication, with sensitive credentials and API keys stored in AWS Secrets Manager. All data is encrypted in transit and at rest, with AES-256 encryption while at rest – and it is continuously monitored for unusual activity, intrusion attempts, and abnormal API usage.

“Executives don’t want to build their own AI agents, and in the admin space, they don’t want to approve every step their assistant makes – they want it done right, in a way they can trust,” says Sabato. “Catch works alongside business leaders the way a great human assistant would, but 24/7, with no dip in attention and fully secure. We’re laser-focused on one thing – executive admin, making the right call in real time.”

Billed at $99/month, Catch claims an improved admin assistant at a fraction of the cost of a human assistant.

Related: DataBahn Raises $40 Million for Agentic Data Pipeline Management

Related: Mate Security Raises $35 Million for Agentic SOC

Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

Related: HiddenLayer Raises $100 Million for AI Runtime Security

https://www.securityweek.com/catch-raises-5-million-for-ai-executive-assistant-with-guardrails/




Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.

The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.

https://www.securityweek.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/




Nvidia buys Hugging Face, the GitHub of AI, for $13 billion

Nvidia has agreed to buy AI model platform Hugging Face for $13 billion, in the latest step by the $5.4 trillion chip giant to use its financial might to accelerate the technology’s boom while exerting greater control over the industry.

Hugging Face, which only last year turned down a large investment from Nvidia at a $7 billion valuation to maintain its independence, serves as a repository for millions of models and data sets and has become a champion of “open” AI systems.

Nvidia said the goal of the deal was to speed up the spread of open models. Unlike proprietary models from labs such as OpenAI and Anthropic, the design of open-weight models is public and users can download, customize and run them on their own hardware.

Read full article

Comments

https://arstechnica.com/ai/2026/09/nvidia-buys-hugging-face-the-github-of-ai-for-13-billion/




AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.

The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.

https://www.securityweek.com/ai-agent-firewall-startup-air-security-emerges-from-stealth-with-50-million/




OpenLeash Adds a Human Check to Risky AI Agent Actions

The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.

The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.

https://www.securityweek.com/openleash-adds-a-human-check-to-risky-ai-agent-actions/




Google releases Gemini 3.8 Flash, its third Flash model in six weeks

Google hasn’t released a frontier-level Gemini Pro AI model since early 2026, but it sure loves rolling out new Gemini Flash variants. Today, Google is announcing its third Flash model release in just six weeks, making it more likely that we’ll never see the promised Gemini 3.5 Pro. But no matter, says Google, because Gemini 3.8 Flash is its best reasoning and coding model yet.

Gemini 3.8 Flash comes in two variations. There’s the standard Flash, which Google describes as a “workhorse” model that’s good for anything from agentic tasks to software development. Then we have Gemini 3.8 Flash Cyber, which runs on the same foundations but has been tuned for vulnerability detection and mitigation.

For developers, Google has the same pitch as it did for the 3.7 Flash release just a couple of weeks ago. API access to the model is available at an “introductory rate” through the end of the year: $0.75 per million input tokens and $3.75 per million output tokens. The regular price will be $1.50 / $7.50, but it’s likely there will be new models available long before the price changes. Google probably sees the lower prices as a necessity given that other AI labs have recently dropped token pricing to keep increasingly wary businesses engaged with AI tools.

Read full article

Comments

https://arstechnica.com/ai/2026/09/google-releases-gemini-3-8-flash-its-third-flash-model-in-six-weeks/




Trump may be forced to reveal secret rules feds use for AI safety testing

Four federal agencies have been sued amid calls to release information about the secret framework that the Trump administration uses to conduct safety reviews of frontier AI models prior to release.

In a Wednesday press release announcing the lawsuit, a nonpartisan nonprofit called Protect Democracy alleged that “almost no details” have been released to the public or Congress. To everyone except a few vague “trusted partners,” it remains unclear what the government’s review process looks like, which companies are involved in constructing the framework, or what legal authority Trump officials have to conduct the reviews.

“Neither the identities of those entities nor the criteria by which they were selected have been made public,” Protect Democracy said.

Read full article

Comments

https://arstechnica.com/tech-policy/2026/09/trump-may-be-forced-to-reveal-secret-rules-feds-use-for-ai-safety-testing/




Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards

Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse.

The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek.

https://www.securityweek.com/anthropic-details-response-to-security-incidents-unveils-enterprise-safeguards/