Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • Columbia University researchers found a new way to hide information in plain text
  • Technology

Columbia University researchers found a new way to hide information in plain text

Do Son May 11, 2018 3 minutes read
FontCode
Add Daily CyberSecurity as a preferred source on Google

Columbia Engineering Computer scientists invented a new method, FontCode, that can embed hidden information in the text without interfering with text. The FontCode creation uses font perturbation to encode information, which can then be decoded to recover the information. Unlike other methods of hiding text and documents embedded with information, this method is suitable for most fonts and document types, even when printing documents or converting to other file types. The study will be presented at SIGGRAPH in Vancouver on August 12-16.

Changxi Zheng, associate professor of computer science and the paper’s senior author said:

“While there are obvious applications for espionage, we think FontCode has even more practical uses for companies wanting to prevent document tampering or protect copyrights, and for retailers and artists wanting to embed QR codes and other metadata without altering the look or layout of a document”

Zheng led his students to create this method of text steganography, which can embed texts, metadata, URLs, or digital signatures into text documents or images, whether digital or paper-based. It works with popular font families such as Times Roman, Helvetica, and Calibri, and is compatible with most word processors (including Word and FrameMaker) and image editing and drawing programs (such as Photoshop and Illustrator). Since each letter may be disturbed, the amount of information secretly conveyed is limited only by the length of the regular text. Information uses subtle font perturbation coding—changing the stroke width, adjusting the height of the ascent and descent, or adjusting the curves of the letters o, p, and b, for example.

Hidden data using FontCode can be very difficult to detect. Even if an attacker detects a font change between two texts, it is impractical to scan every file in the company.

Data hidden using FontCode can be extremely difficult to detect. Even if an attacker detects font changes between two texts—highly unlikely given the subtlety of the perturbations—it simply isn’t practical to scan every file going and coming within a company. “Encryption is just a backup level of protection in case an attacker can detect the use of font changes to convey secret information,” says Zheng. “It’s very difficult to see the changes, so they are really hard to detect—this makes FontCode a very powerful technique to get data past existing defenses.”

The research author has submitted a patent to Columbia Technology Ventures and plans to extend FontCode to other languages and character sets, including Chinese.

“We are excited about the broad array of applications for FontCode,” said Zheng. “from document management software, to invisible QR codes, to protection of legal documents. FontCode could be a game changer..”

Suggest Reading:

FontCode: Embedding Information in Text Documents using Glyph Perturbation

Source: TechXplore 

Related coverage

  • Cloud Wars: OpenAI Signs $38 Billion Computing Deal with AWS, Ending Microsoft Exclusivity
  • Google Cloud Services Disrupted in UK Due to Power Outage
  • iPhone 17 Pro Max Users Report Distorted Audio and Static Noise During USB-C Charging
  • Intel: CPUs affected by the vulnerabilities will be fully repaired by the end of January
  • Google Drive Desktop Gets Major Redesign: Unified UI Centralizes Files, Sync & Notifications
  • Bezos’ $100 Billion Gamble: The Clandestine “Project Prometheus” Plan to Buy and AI-Overhaul Global Industry
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: FontCode

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-82531CVSS 9.2
    Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never...
    📅 Updated: Oct 6, 2026
  • CVE-2025-12543CVSS 9.6
    A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and...
    📅 Updated: Oct 6, 2026
  • CVE-2026-85153CVSS 9.3
    This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in...
    📅 Updated: Oct 6, 2026
  • CVE-2026-42415CVSS 9.3
    Unauthenticated SQL Injection in Porto Theme - Functionality
    📅 Updated: Oct 6, 2026
  • CVE-2026-42417CVSS 9.3
    Unauthenticated SQL Injection in ARMember Premium
    📅 Updated: Oct 6, 2026
  • CVE-2026-41555CVSS 9.3
    Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email
    📅 Updated: Oct 6, 2026
  • CVE-2026-39795CVSS 9.3
    Unauthenticated SQL Injection in SendPress Newsletters
    📅 Updated: Oct 6, 2026
  • CVE-2026-39797CVSS 9.8
    Unauthenticated PHP Object Injection in GDPR Framework By Data443
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.