UPDATED 09:00 EST / SEPTEMBER 11 2025

SECURITY

New open-source tool from Permiso uncovers dangerous inbox rule blind spots

Identity threat detection and response startup Permiso Security Inc. today released a new open-source tool designed to help enterprises detect and mitigate a new class of obfuscation attacks that exploit Microsoft Exchange inbox rules.

The new tool seeks to deal with what research from Permisso dubs “Inboxfuscation.” It’s a Unicode-based evasion technique that can create malicious rules invisible to traditional monitoring systems, potentially allowing attackers to establish persistence and exfiltrate sensitive communications undetected.

Historically, malicious inbox rules have been relatively simple for defenders to flag, often relying on obvious keywords such as “password” or “admin.” Security teams could spot these through keyword detection or regex matching, but with Inboxfuscation, attackers can craft rules with visually identical characters that evade existing defenses.

Techniques include mathematical alphanumeric substitutions, zero-width characters, bidirectional text controls and enclosed alphanumerics, all of which can render malicious rules nearly indistinguishable from legitimate ones.

Permiso warns that though it has not yet observed these techniques in active campaigns, their feasibility represents a looming blind spot for defenders.

The company’s research outlines several hypothetical scenarios where attackers could leverage Inboxfuscation, from long-term advanced persistent threat operations exfiltrating executive emails to insider threats monitoring human resource communications or deleting security alerts to hide intrusions. In each case, traditional tools would struggle to recognize the obfuscated rules.

To address the potential risk, Permiso has developed a detection tool capable of analyzing suspicious Unicode categories, parsing multiple log formats and recognizing behavioral patterns across Exchange environments.

The new tool integrates with existing security information and event management systems to provide structured outputs with risk scores, mailbox details and suspicious fields. Permiso has made the project freely available on GitHub and is encouraging security teams to test their detection capabilities, build Unicode-aware monitoring systems and conduct proactive threat hunting.

“The Inboxfuscation research demonstrates a significant vulnerability in current email security architectures,” Permiso wrote in a blog post. “While these techniques have not yet been observed in active threat campaigns, the technical feasibility and detection challenges suggest they represent a future threat vector that security teams should prepare for today. By developing proactive detection capabilities and understanding the technical mechanisms of Unicode obfuscation, organizations can stay ahead of potential attackers who may discover and weaponize these techniques.”

Image: SiliconANGLE/Sora

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.