A new email attack uses seemingly harmless SVG image files to deliver JavaScript-based redirects to malicious websites. These SVGs, often embedded in emails or linked externally, bypass many security systems because they are treated as benign images. Attackers use spoofed domains and pushy email subject lines to trick users. Experts advise deleting unexpected emails with SVG attachments or image links and disabling automatic image loading in your browser. This attack leverages user complacency, exploiting the assumption that images are safe.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments