{"id":4020,"date":"2026-09-04T10:00:24","date_gmt":"2026-09-04T09:00:24","guid":{"rendered":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/"},"modified":"2026-09-04T10:00:26","modified_gmt":"2026-09-04T09:00:26","slug":"ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion","status":"publish","type":"post","link":"https:\/\/www.whysecurity.it\/en\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/","title":{"rendered":"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion"},"content":{"rendered":"<p>Microsoft researchers have identified a significant phishing campaign that repurposes &#8216;ASCII smuggling&#8217;\u2014a technique originally popularized in AI prompt injection research\u2014to bypass email security filters. Instead of hiding malicious instructions from humans to target AI models, attackers are using invisible Unicode tag characters (U+E0000 to U+E007F) to fracture high-signal keywords like &#8216;funding&#8217; into &#8216;fun\u27e8U+E0020\u27e9ding&#8217;.<\/p>\n<h3>What is ASCII Smuggling?<\/h3>\n<p>ASCII smuggling involves embedding invisible Unicode tag characters within text. These characters are typically ignored by standard fonts and user interfaces, rendering them invisible to human readers. However, they remain present in the raw data, allowing attackers to break up keywords that would otherwise be caught by security detectors. While originally developed to smuggle instructions into LLMs, this campaign demonstrates an &#8216;inverted&#8217; use case: filter evasion.<\/p>\n<h3>Observations and Campaign Mechanics<\/h3>\n<p>Microsoft telemetry noted a massive spike in these signatures starting February 9, 2026, peaking at over 2.3 million messages daily. The campaign exhibited several distinct characteristics:<\/p>\n<ul>\n<li><strong>Strict Cadence:<\/strong> The activity followed a clear weekly rhythm, firing heavily on weekdays and going silent on weekends.<\/li>\n<li><strong>Infrastructure:<\/strong> The phishing emails were routed through legitimate email-marketing platforms (ActiveCampaign) to leverage their established IP reputation.<\/li>\n<li><strong>Disposable Domains:<\/strong> Attackers used hundreds of finance-themed domains, constructed by recombining a small set of business-related tokens (e.g., &#8216;capital&#8217;, &#8216;boost&#8217;, &#8216;loan&#8217;).<\/li>\n<\/ul>\n<h3>Is There a Detection Gap?<\/h3>\n<p>This technique highlights a potential blind spot for security pipelines that do not normalize text before evaluation. If a detection system processes tokens in a way that doesn&#8217;t account for interleaved invisible characters, it may fail to recognize common phishing lures. Conversely, because these characters appear so rarely in legitimate traffic, their presence serves as a high-confidence anomaly signal for defenders.<\/p>\n<h3>Mitigation and Protection Guidance<\/h3>\n<p>Microsoft recommends that organizations adopt a &#8216;normalize before match&#8217; approach. Key defensive steps include:<\/p>\n<ol>\n<li><strong>Normalization:<\/strong> Strip all invisible Unicode tag characters (U+E0000-U+E007F) and other zero-width code points from email subject lines and body content before applying security signatures.<\/li>\n<li><strong>Anomaly Detection:<\/strong> Flag the presence of these Unicode tag blocks as a high-value security signal, while accounting for legitimate exceptions like specific subdivision flag emojis.<\/li>\n<li><strong>Behavioral Analysis:<\/strong> Utilize infrastructure patterns\u2014such as the rotation of finance-themed domains relayed through marketing platforms\u2014to identify and block campaigns even when obfuscation methods evolve.<\/li>\n<\/ol>\n<p>As AI-era attack methods continue to be integrated into traditional phishing ecosystems, defenders must employ a cross-domain lens to secure both human and AI-driven communication channels.<\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft researchers have identified a significant phishing campaign that repurposes &#8216;ASCII smuggling&#8217;\u2014a technique originally popularized in AI prompt injection research\u2014to bypass email security filters. Instead of hiding malicious instructions from humans to target AI models, attackers are using invisible Unicode tag characters (U+E0000 to U+E007F) to fracture high-signal keywords like &#8216;funding&#8217; into &#8216;fun\u27e8U+E0020\u27e9ding&#8217;. What is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4021,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4020","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ASCII Smuggling: From AI Prompt Injection to Phishing Evasion - CyberSecurity Experts<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.whysecurity.it\/en\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion - CyberSecurity Experts\" \/>\n<meta property=\"og:description\" content=\"Microsoft researchers have identified a significant phishing campaign that repurposes &#8216;ASCII smuggling&#8217;\u2014a technique originally popularized in AI prompt injection research\u2014to bypass email security filters. Instead of hiding malicious instructions from humans to target AI models, attackers are using invisible Unicode tag characters (U+E0000 to U+E007F) to fracture high-signal keywords like &#8216;funding&#8217; into &#8216;fun\u27e8U+E0020\u27e9ding&#8217;. What is [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.whysecurity.it\/en\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/\" \/>\n<meta property=\"og:site_name\" content=\"CyberSecurity Experts\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/whysec\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-04T09:00:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-04T09:00:26+00:00\" \/>\n<meta name=\"author\" content=\"whysecurity\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"whysecurity\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/\"},\"author\":{\"name\":\"whysecurity\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/person\\\/aa3b7e95e9fd51fd7f39d48911fdfe0a\"},\"headline\":\"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion\",\"datePublished\":\"2026-09-04T09:00:24+00:00\",\"dateModified\":\"2026-09-04T09:00:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/\"},\"wordCount\":414,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine.jpg\",\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/\",\"name\":\"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion - CyberSecurity Experts\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine.jpg\",\"datePublished\":\"2026-09-04T09:00:24+00:00\",\"dateModified\":\"2026-09-04T09:00:26+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine.jpg\",\"contentUrl\":\"https:\\\/\\\/www.whysecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/immagine.jpg\",\"width\":940,\"height\":627},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.whysecurity.it\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#website\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/\",\"name\":\"WhySecurity\",\"description\":\"Cyber Security Network Services\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.whysecurity.it\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#organization\",\"name\":\"WhySecurity\",\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/tempnewweb.whysecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/logo_white.png\",\"contentUrl\":\"https:\\\/\\\/tempnewweb.whysecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/logo_white.png\",\"width\":500,\"height\":91,\"caption\":\"WhySecurity\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/whysec\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.whysecurity.it\\\/#\\\/schema\\\/person\\\/aa3b7e95e9fd51fd7f39d48911fdfe0a\",\"name\":\"whysecurity\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g\",\"caption\":\"whysecurity\"},\"sameAs\":[\"https:\\\/\\\/whysecurity.it\"],\"url\":\"https:\\\/\\\/www.whysecurity.it\\\/en\\\/author\\\/whysecurity\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion - CyberSecurity Experts","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.whysecurity.it\/en\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/","og_locale":"en_US","og_type":"article","og_title":"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion - CyberSecurity Experts","og_description":"Microsoft researchers have identified a significant phishing campaign that repurposes &#8216;ASCII smuggling&#8217;\u2014a technique originally popularized in AI prompt injection research\u2014to bypass email security filters. Instead of hiding malicious instructions from humans to target AI models, attackers are using invisible Unicode tag characters (U+E0000 to U+E007F) to fracture high-signal keywords like &#8216;funding&#8217; into &#8216;fun\u27e8U+E0020\u27e9ding&#8217;. What is [&hellip;]","og_url":"https:\/\/www.whysecurity.it\/en\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/","og_site_name":"CyberSecurity Experts","article_publisher":"https:\/\/www.facebook.com\/whysec","article_published_time":"2026-09-04T09:00:24+00:00","article_modified_time":"2026-09-04T09:00:26+00:00","author":"whysecurity","twitter_card":"summary_large_image","twitter_misc":{"Written by":"whysecurity","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#article","isPartOf":{"@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/"},"author":{"name":"whysecurity","@id":"https:\/\/www.whysecurity.it\/#\/schema\/person\/aa3b7e95e9fd51fd7f39d48911fdfe0a"},"headline":"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion","datePublished":"2026-09-04T09:00:24+00:00","dateModified":"2026-09-04T09:00:26+00:00","mainEntityOfPage":{"@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/"},"wordCount":414,"commentCount":0,"publisher":{"@id":"https:\/\/www.whysecurity.it\/#organization"},"image":{"@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#primaryimage"},"thumbnailUrl":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine.jpg","articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/","url":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/","name":"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion - CyberSecurity Experts","isPartOf":{"@id":"https:\/\/www.whysecurity.it\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#primaryimage"},"image":{"@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#primaryimage"},"thumbnailUrl":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine.jpg","datePublished":"2026-09-04T09:00:24+00:00","dateModified":"2026-09-04T09:00:26+00:00","breadcrumb":{"@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#primaryimage","url":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine.jpg","contentUrl":"https:\/\/www.whysecurity.it\/wp-content\/uploads\/2026\/09\/immagine.jpg","width":940,"height":627},{"@type":"BreadcrumbList","@id":"https:\/\/www.whysecurity.it\/ascii-smuggling-from-ai-prompt-injection-to-phishing-evasion\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.whysecurity.it\/"},{"@type":"ListItem","position":2,"name":"ASCII Smuggling: From AI Prompt Injection to Phishing Evasion"}]},{"@type":"WebSite","@id":"https:\/\/www.whysecurity.it\/#website","url":"https:\/\/www.whysecurity.it\/","name":"WhySecurity","description":"Cyber Security Network Services","publisher":{"@id":"https:\/\/www.whysecurity.it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.whysecurity.it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.whysecurity.it\/#organization","name":"WhySecurity","url":"https:\/\/www.whysecurity.it\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.whysecurity.it\/#\/schema\/logo\/image\/","url":"https:\/\/tempnewweb.whysecurity.it\/wp-content\/uploads\/2025\/10\/logo_white.png","contentUrl":"https:\/\/tempnewweb.whysecurity.it\/wp-content\/uploads\/2025\/10\/logo_white.png","width":500,"height":91,"caption":"WhySecurity"},"image":{"@id":"https:\/\/www.whysecurity.it\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/whysec"]},{"@type":"Person","@id":"https:\/\/www.whysecurity.it\/#\/schema\/person\/aa3b7e95e9fd51fd7f39d48911fdfe0a","name":"whysecurity","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ca59ad0cd8de5b2222178a2dfd751991a577b51363cd53356ed10b18f5c54a2c?s=96&d=mm&r=g","caption":"whysecurity"},"sameAs":["https:\/\/whysecurity.it"],"url":"https:\/\/www.whysecurity.it\/en\/author\/whysecurity\/"}]}},"_links":{"self":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts\/4020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/comments?post=4020"}],"version-history":[{"count":1,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts\/4020\/revisions"}],"predecessor-version":[{"id":4022,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/posts\/4020\/revisions\/4022"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/media\/4021"}],"wp:attachment":[{"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/media?parent=4020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/categories?post=4020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whysecurity.it\/en\/wp-json\/wp\/v2\/tags?post=4020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}