logo
Delete Any Emails That Include These Images On Your Phone Or PC

Delete Any Emails That Include These Images On Your Phone Or PC

Forbes19-07-2025
You will not see this attack. getty
Republished on July 19 with new analysis into this dangerous image email attack.
Here we go again. There's a fast growing threat in your inbox that's hard to detect — even for security software on your PC. This has 'seemingly come out of nowhere,' but you need to be aware. And it means deleting a raft of incoming emails.
The new warning comes courtesy of Ontinue , which says 'threat actors are increasingly leveraging Scalable Vector Graphics (SVG) files as a delivery vector for JavaScript-based redirect attacks.' Plenty of these images, 'commonly treated as harmless' contain 'embedded script elements' that lead to browser redirects. And that's a huge risk.
While these images might be .SVG attachments, as we have seen before, they could also be links to external images pulled into the email. And the campaign also relies on spoofed domains and email lures to trick users into opening and engaging. Forbes Apple's Next iPhone Upgrade May Be Bad News For Google By Zak Doffman
As Sophos explains, the SVG file format 'is designed as a method to draw resizable, vector-based images on a computer. By default, SVG files open in the default browser on Windows computers. But SVG files are not just composed of binary data, like the more familiar JPEG, PNG, or BMP file formats. SVG files contain text instructions in an XML format for drawing their pictures in a browser window.'
VIPRE warns that 'up until this point, SVGs have been recognized by email security tools as generally benign image files, which is why attackers are now having so much success hiding their nefarious exploits in them.'
Looking at these latest attacks, SlashNext's J Stephen Kowski told me 'when you open or preview these 'images,' they can secretly redirect your browser to dangerous websites without you knowing.' That means you need to be 'extra careful' with images.
Because these attackers leverage spoofed domains and senders to trick you, it isn't as easy as just avoiding emails from unknown senders. Instead, you should delete any email with an .SVG attachment unless you're expecting it. And you should allow your browser to block external images until you're certain of their origin.
Kowski says these emails will also likely be 'pushy about viewing the image right away,' and while 'your email provider's built-in security features, such as spam filtering and safe attachments, can help, they're not perfect against these newer tricks.'
Jason Soroko from Sectigo goes even further, warning security teams to 'treat every inbound SVG as a potential executable,' as the surge in such attacks continues.
The real threat though lies in user complacency. SVG attacks, VIPRE says, are now tussling with PDFs to become 'attackers' favorite attachments of choice.' These are only images, most users assume, and so no click-throughs, no harm. Forbes Apple Warning—Do Not Make These Calls On Your iPhone By Zak Doffman
Bambenek Consulting's John Bambenek says this is 'a fresh spin on the technique of using image files for delivering suspect content, in this case, malicious PDFs. The attackers have to rely on complacency ('it's only an image, it doesn't execute code') to lull organizations into accepting this content and getting it on the inside of a network.'
Ontinue says 'the observed targets of this campaign fall into B2B Service Providers, including the ones handling valuable Corporate Data regularly, including Financial and Employee data, Utilities, Software-as-a-Service providers that are great social engineering targets as they expect to receive a high volume of emails.'
The payload itself 'is delivered via an .SVG file that contains a JavaScript block hidden within a CDATA section. The embedded code uses a static XOR key to decrypt a secondary payload at runtime. This decoded script reconstructs and executes a redirect command using the Function() constructor.'
And the team warns 'this technique demonstrates how adversaries are shifting away from executable payloads and towards smuggling (HTML and now SVG) techniques. By embedding script logic into image formats and using trusted browser functions, the attack chain avoids triggering traditional behavioral or signature-based alerts.'
The emails containing the attachments or links will be simple, 'using a minimal format to avoid detection and provoke curiosity or interaction.' Hijacking poorly protected domains or spoofing others with special characters enhances the lure.
'While this report and research is valuable to enterprises,' Bambenek says, 'and the search valuable for hunt teams, organizations without a security staff or end consumers will remain vulnerable to conventional cybercrime with this technique.'
'This SVG attack vector is exactly what we've been tracking,' Kowski warns. 'Attackers have exhausted much of the text-based social engineering playbook over the last ten years and are now getting creative with content payloads to execute malicious code.' And this is easily done because 'attackers can easily spoof trusted senders, making recipients more likely to open what appears to be an innocent image file.' Forbes Do Not Use This WiFi Setting On Your iPhone Or Android Phone By Zak Doffman
'The beauty of SVG files from an attacker's perspective,' he told me, 'is that they look like harmless images but can contain embedded JavaScript that runs the moment someone opens the file in a browser, bypassing traditional email security that focuses on executable attachments.' Which means users need a new defensive playbook.
And so the advice is just as simple. If you're not expecting an email which includes image links or .SVG attachments, delete them from your inbox. 'This campaign highlights a creative pivot in attacker methodology,' the team says, 'using benign file formats to hide malicious logic and evade established detection controls.'
Which is another way of saying that you're your own best defense.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Tesla ordered by Florida jury to pay $329 million in Autopilot crash
Tesla ordered by Florida jury to pay $329 million in Autopilot crash

Yahoo

time2 minutes ago

  • Yahoo

Tesla ordered by Florida jury to pay $329 million in Autopilot crash

(Reuters) -A Florida jury on Friday found Tesla liable in the 2019 fatal crash of an Autopilot-equipped Model S, and ordered Elon Musk's automaker to pay $329 million to the family of a deceased woman and an injured survivor. The payout includes $129 million of compensatory damages and $200 million of punitive damages. Tesla was sued by the estate of Naibel Benavides Leon, and by her former boyfriend Dillon Angulo. The lawsuit concerned an April 25, 2019 incident where George McGee drove his 2019 Model S at about 62 mph (100 kph) through an intersection into the victims' parked Chevrolet Tahoe as they were standing beside it on a shoulder. "Tesla designed Autopilot only for controlled access highways yet deliberately chose not to restrict drivers from using it elsewhere," Brett Schreiber, a lawyer for the plaintiffs, said in a statement. "Today's verdict represents justice for Naibel's tragic death and Dillon's lifelong injuries." Tesla did not immediately respond to requests for comment. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

Android TV is getting ready to kill off the Discover tab... last month? (APK teardown)
Android TV is getting ready to kill off the Discover tab... last month? (APK teardown)

Android Authority

time3 minutes ago

  • Android Authority

Android TV is getting ready to kill off the Discover tab... last month? (APK teardown)

Aamir Siddiqui / Android Authority TL;DR Android TV currently offers a Discover tab for getting recommendations and building your watchlist. A new update to the system launcher suggests that Google's planning to drop Discover and move your watchlist to the Home tab. Confusingly, Google's messaging in the app suggest that this change was supposed to take place in July. What does your usage of Android TV look like? Google's big-screen entertainment platform certainly tries to act as a hub that not just organizes all your streaming options in one place, but helps steer you in the direction of what you might want to check out next. Are you taking advantage of that, though, checking in on the Discover tab to get some recommendations from Google? Or are you more likely to dive right in to your favorite streaming app itself, and learn about what's new on a service-by-service basis? We wonder just how many users fall into that latter camp — and Google probably has been too, as the company seems to be getting ready to kill off Discover as we know it. ⚠️ An APK teardown helps predict features that may arrive on a service in the future based on work-in-progress code. However, it is possible that such predicted features may not make it to a public release. At least, Google sure looks like it was getting ready to put an end to the Discover tab in Android TV. We're just a little less than sure if that plan is still in motion. Looking over the changes in Google's 7.1.7-787904429-f update for the Android TV Home app — basically the Android TV launcher that provides the base UI — we've identified some new text strings that reference plans to remove Discover: Code Copy Text Your recommendations and watchlist will move to the 'Home' tab. The Discover tab is going away soon The Home tab can already function as a reasonable enough tool for finding new content, especially when you add a few channel rows for your favorite apps. Consolidating Discover recommendations there makes enough sense if Google's looking to clean up some of Android TV's sprawl, and bringing the watchlist along sounds just fine. Considering how straightforward those strings read, where's our confusion coming from? Well, we also found these new strings: Code Copy Text The Discover tab was removed in July 2025. Also, customise your recommendation is on Home tab Your watchlist have moved to Home tab Today marks the start of August, and we're still seeing the Discover tab on all the Android TV devices we checked. More than that, we haven't yet seen the 'going away soon' message displayed, which sure seems intended to give users a bit of a heads-up in advance of the removal. For the moment, color us a little confused about Google's intentions here. Perhaps plans to kill Discover have already been canceled, but this unused code still managed to sneak in to a public build. Or maybe Discover really will be going away, but Google's had to push its timetable back a little. We'll keep an eye out for any further Android TV updates that might shed more light on the company's plans. Follow

Bose's QuietComfort Headphones are $130 off for back-to-school season
Bose's QuietComfort Headphones are $130 off for back-to-school season

The Verge

time4 minutes ago

  • The Verge

Bose's QuietComfort Headphones are $130 off for back-to-school season

Finding peace among the chaos on campus can be more challenging than a midterm. But a quality pair of over-ear headphones can block out distractions when it's time to lock in. If that sounds like you, we've found a deal on the Bose QuietComfort Headphones, which are currently down to $229 ($130 off) at Amazon, Bose, and Best Buy. That's within $30 of the lowest price we've seen all year. The Bose QuietComfort Headphones are part of the company's revamped lineup of headphones and earbuds, which also includes the pricier QC Ultra Headphones, QC Ultra Earbuds, and entry-level QC Earbuds, the last of which is down to $149 ($30 off) at Amazon, Bose, and Best Buy. The QC Headphones preserve the comfortable design of the QC45s and include Bose's excellent noise cancellation. Although we haven't reviewed this specific model, the upgraded QC Headphones Ultra is our favorite noise-canceling headphones for travel, and we're generally fans of the line's comfortable earcup cushions. There are two listening modes — Quiet and Aware — that let you quickly toggle between blocking the outside world and letting ambient noise in. Additionally, Bose says the QC headphones offer up to 24 hours of battery life, so you should be able to get through a full day without needing to recharge. The headphones also support multipoint connectivity, making it possible to pair them with two devices simultaneously. And when you're finally done writing that last-minute term paper, the QC headphones can neatly fold up to make it easier to store them in your bag. Sign up for Verge Deals to get deals on products we've tested sent to your inbox weekly. Posts from this author will be added to your daily email digest and your homepage feed. See All by Brandon Russell Posts from this topic will be added to your daily email digest and your homepage feed. See All Deals Posts from this topic will be added to your daily email digest and your homepage feed. See All Gadgets Posts from this topic will be added to your daily email digest and your homepage feed. See All Headphones Posts from this topic will be added to your daily email digest and your homepage feed. See All Tech

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store