Watch Your Language: Detecting Multi-Lingual Language-Confusion Phishing

Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.