{"id":697131,"date":"2026-07-17T18:55:10","date_gmt":"2026-07-17T18:55:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/697131\/"},"modified":"2026-07-17T18:55:10","modified_gmt":"2026-07-17T18:55:10","slug":"ai-spam-filters-are-getting-suckered-by-old-school-text-salting","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/697131\/","title":{"rendered":"AI spam filters are getting suckered by old-school text salting"},"content":{"rendered":"<p class=\"kicker \" style=\"\">security<\/p>\n<p class=\"subtitle \" style=\"\">Turns out decades-old email tricks still work against some LLM-powered email filters<\/p>\n<p>Notice more spam getting through that corporate email filter lately? Attackers are using a technique known as &#8220;text salting,&#8221; which hides benign-looking words intended to confuse some AI-powered email filters, says cybersecurity firm Barracuda.<\/p>\n<p>The email security outfit <a href=\"https:\/\/blog.barracuda.com\/2026\/07\/16\/text-salting-ai-email-security\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a>\u00a0on Thursday that it had detected more than one million retail-themed phishing attacks using text salting since April. It\u2019s not a new technique by any stretch and has been used to fool traditional secure email gateways for years, but Barracuda says it can also confuse machine-learning and LLM-based security tools.<\/p>\n<p>Text salting involves peppering (sorry) a malicious email with random, harmless-seeming words in order to fool an email scanning system into thinking there\u2019s nothing off about the flavor of a message (sorry again), tricking the system into passing it to its recipient for consumption (I\u2019ll stop with the food jokes here).\u00a0<\/p>\n<p>Pour a pile of salty text on top of an email and a human reader would probably get suspicious, however, so attackers typically use one or more of three flavor variations (okay, I&#8217;m done \u2013 promise) to hide the additives from human readers, but not automated scanners, per Barracuda.<\/p>\n<p>Typical techniques include CSS cropping, which sets the visible window small enough that a human won&#8217;t see the hidden filler text; text manipulation to move the salty copy outside the visible screen; and zero font techniques which insert misleading words between suspicious phishing copy that\u2019s visible to a machine but not a human.\u00a0<\/p>\n<p>The end result of each of those techniques is a message that reads less malicious, more gibberish to a machine, leading it to assume the email is fine, and which looks exactly as the attacker intended when viewed by a human.\u00a0<\/p>\n<p>Modern email security systems have largely adapted to these techniques, with newer tools able to remove hidden text to see what a reader is supposed to see, sounding alarms when a lot of hidden stuff is inserted in an email, and the like. AI, however, hasn\u2019t managed to follow suit, says Barracuda.\u00a0<\/p>\n<p>\u201cText salting and related techniques can be used to confuse AI-driven content analysis engines by flooding the email with random terms that encourage the AI system into making an incorrect classification decision,\u201d the company wrote in its report &#8211; just like those early 2000s SEGs. What a technological leap we\u2019ve made!<\/p>\n<p>LLMs, Barracuda explained, are typically designed to process email text and source code plainly, with no understanding of whether text is visible or hidden from a user. They can be trained to do so, but that just means most tools probably aren\u2019t doing that by default.\u00a0<\/p>\n<p>So, what can enterprises do to stop the flow of salty spam to their employees? Barracuda recommends a layered approach to email security rather than relying solely on keyword detection, including checking sender reputation, authentication results, embedded URLs, HTML-rendering techniques, and differences between user-visible and hidden content.<\/p>\n<p>Ditching that AI spam filter might not be a bad idea, either. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security Turns out decades-old email tricks still work against some LLM-powered email filters Notice more spam getting through&hellip;\n","protected":false},"author":2,"featured_media":697132,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-697131","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/697131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=697131"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/697131\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/697132"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=697131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=697131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=697131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}