Punycode being an attack vector is recently in the news:
arstechnica.com
just a reminder that Firefox has an attempt at some mitigations:
With help from Google, impersonated Brave.com website pushes malware
With a valid TLS certificate, faux Bravė.com could fool even security-savvy people.
arstechnica.com
Show IDN punycode in Firefox to avoid phishing URLs
Enable the network.IDN_show_punycode flag in Firefox's about:config to unmask IDN homograph domains and spot phishing URLs at a glance.
ma.ttias.be

