Bottom line: Successful attacks exploiting invisible Unicode characters can compromise user authentication and sensitive data.
What's happening: An attacker exploited a Unicode invisible character in phishing emails sent to employees at a US-based company, which uses Microsoft Office 365. The attack exploited a known vulnerability (CVE-2020-1234) in Microsoft's Office 365 software, allowing the attacker to bypass authentication mechanisms.
What to do: Security teams should review their phishing filter configurations to ensure they account for invisible Unicode characters. Additionally, organizations should consider implementing security awareness training to educate employees on the risks of these types of attacks.