A new XSS WAF bypass technique has been discovered using invisible separators before or after the function name. The payload <img/src/onerror=alert&#xFEFF;(1337)><svg/onload=&nbsp;alert&#65279;(2)> can be used to exploit this vulnerability. Ethical hackers can use this technique to bypass XSS WAF protections. For more technical details, refer to the tweet.