
Delete Any Emails That Include These Images On Your Phone Or PC
Republished on July 19 with new analysis into this dangerous image email attack.
Here we go again. There's a fast growing threat in your inbox that's hard to detect — even for security software on your PC. This has 'seemingly come out of nowhere,' but you need to be aware. And it means deleting a raft of incoming emails.
The new warning comes courtesy of Ontinue , which says 'threat actors are increasingly leveraging Scalable Vector Graphics (SVG) files as a delivery vector for JavaScript-based redirect attacks.' Plenty of these images, 'commonly treated as harmless' contain 'embedded script elements' that lead to browser redirects. And that's a huge risk.
While these images might be .SVG attachments, as we have seen before, they could also be links to external images pulled into the email. And the campaign also relies on spoofed domains and email lures to trick users into opening and engaging. Forbes Apple's Next iPhone Upgrade May Be Bad News For Google By Zak Doffman
As Sophos explains, the SVG file format 'is designed as a method to draw resizable, vector-based images on a computer. By default, SVG files open in the default browser on Windows computers. But SVG files are not just composed of binary data, like the more familiar JPEG, PNG, or BMP file formats. SVG files contain text instructions in an XML format for drawing their pictures in a browser window.'
VIPRE warns that 'up until this point, SVGs have been recognized by email security tools as generally benign image files, which is why attackers are now having so much success hiding their nefarious exploits in them.'
Looking at these latest attacks, SlashNext's J Stephen Kowski told me 'when you open or preview these 'images,' they can secretly redirect your browser to dangerous websites without you knowing.' That means you need to be 'extra careful' with images.
Because these attackers leverage spoofed domains and senders to trick you, it isn't as easy as just avoiding emails from unknown senders. Instead, you should delete any email with an .SVG attachment unless you're expecting it. And you should allow your browser to block external images until you're certain of their origin.
Kowski says these emails will also likely be 'pushy about viewing the image right away,' and while 'your email provider's built-in security features, such as spam filtering and safe attachments, can help, they're not perfect against these newer tricks.'
Jason Soroko from Sectigo goes even further, warning security teams to 'treat every inbound SVG as a potential executable,' as the surge in such attacks continues.
The real threat though lies in user complacency. SVG attacks, VIPRE says, are now tussling with PDFs to become 'attackers' favorite attachments of choice.' These are only images, most users assume, and so no click-throughs, no harm. Forbes Apple Warning—Do Not Make These Calls On Your iPhone By Zak Doffman
Bambenek Consulting's John Bambenek says this is 'a fresh spin on the technique of using image files for delivering suspect content, in this case, malicious PDFs. The attackers have to rely on complacency ('it's only an image, it doesn't execute code') to lull organizations into accepting this content and getting it on the inside of a network.'
Ontinue says 'the observed targets of this campaign fall into B2B Service Providers, including the ones handling valuable Corporate Data regularly, including Financial and Employee data, Utilities, Software-as-a-Service providers that are great social engineering targets as they expect to receive a high volume of emails.'
The payload itself 'is delivered via an .SVG file that contains a JavaScript block hidden within a CDATA section. The embedded code uses a static XOR key to decrypt a secondary payload at runtime. This decoded script reconstructs and executes a redirect command using the Function() constructor.'
And the team warns 'this technique demonstrates how adversaries are shifting away from executable payloads and towards smuggling (HTML and now SVG) techniques. By embedding script logic into image formats and using trusted browser functions, the attack chain avoids triggering traditional behavioral or signature-based alerts.'
The emails containing the attachments or links will be simple, 'using a minimal format to avoid detection and provoke curiosity or interaction.' Hijacking poorly protected domains or spoofing others with special characters enhances the lure.
'While this report and research is valuable to enterprises,' Bambenek says, 'and the search valuable for hunt teams, organizations without a security staff or end consumers will remain vulnerable to conventional cybercrime with this technique.'
'This SVG attack vector is exactly what we've been tracking,' Kowski warns. 'Attackers have exhausted much of the text-based social engineering playbook over the last ten years and are now getting creative with content payloads to execute malicious code.' And this is easily done because 'attackers can easily spoof trusted senders, making recipients more likely to open what appears to be an innocent image file.' Forbes Do Not Use This WiFi Setting On Your iPhone Or Android Phone By Zak Doffman
'The beauty of SVG files from an attacker's perspective,' he told me, 'is that they look like harmless images but can contain embedded JavaScript that runs the moment someone opens the file in a browser, bypassing traditional email security that focuses on executable attachments.' Which means users need a new defensive playbook.
And so the advice is just as simple. If you're not expecting an email which includes image links or .SVG attachments, delete them from your inbox. 'This campaign highlights a creative pivot in attacker methodology,' the team says, 'using benign file formats to hide malicious logic and evade established detection controls.'
Which is another way of saying that you're your own best defense.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Forbes
6 minutes ago
- Forbes
AI Fears Become Reality In The Tech Industry
This is a published version of Forbes' Careers Newsletter. Click here to subscribe and get it in your inbox every Tuesday. Fears of AI taking over jobs is already becoming a reality in tech. Fears of artificial intelligence costing people their jobs are already proving to be true. Or at the very least, CEOs are now admitting to the technology's impact as AI-related layoffs ramp up, especially in the tech industry, reports Forbes' Richard Nieva. Fiverr CEO Micha Kaufman is just the latest to say out loud that AI is already a threat to all kinds of jobs—including his. In an April memo to his 1,200 employees, he wrote: 'AI is coming for your jobs. Heck, it's coming for my job too.' 'I hear the conversation around the office. I hear developers ask each other, 'Guys, are we going to have a job in two years?'' Kaufman tells Forbes now. 'I felt like this needed validation from me—that they aren't imagining stuff.' He joins the likes of Andy Jassy at Amazon, Anthropic's Dario Amodei and Shopify's Tobi Lutke in admitting that AI will replace humans in white-collar jobs, some going as far as predicting a 'white-collar bloodbath.' The impacts are already being felt, particularly for young coders and entry-level workers. The total number of employed entry-level developers from ages 18 to 25 has dropped 'slightly' since 2022, after the launch of ChatGPT, said Ruyu Chen, a postdoctoral fellow at the Digital Economy Lab of Stanford's Institute for Human-Centered AI. But not everything can, or should, be automated just yet. Take the buy-now-pay-later firm Klarna, for example, which last year slashed its workforce by 40% in part to the company's investments in AI. A year later, it launched a massive recruiting push for human customer service agents. 'We have noticed that in a world where everything is automated,' Klarna spokesperson Clare Nordstrom told Forbes, 'people put a premium on the human experience.' Happy reading, and hope you have a lovely week! WORK SMARTER Practical insights and advice from Forbes staff and contributors to help you succeed in your job, accelerate your career and lead smarter. Why mastering 'systems-thinking' skills could protect your job from AI. What to do when someone is hired above you. Amid all the hype, here's why you may not need an AI agent. TOUCH BASE News from the world of work. Looking for lower costs, different lifestyles and less toxic politics, more Americans are considering retiring abroad. In its annual Best Places To Retire Abroad, list, Forbes ranked the 24 countries and 96 spots that could make the most sense for retirees looking outside the U.S. Beloved office snacks might soon be a thing of the past, thanks to Congress. Despite luring workers back into the office with the promise of free food, employers will no longer be able to deduct the cost of the food they provide for their employees as part of President Donald Trump's Big Beautiful Bill. The only exceptions: restaurants and the Alaskan fishing industry. One seemingly innocuous kiss cam at a Boston Coldplay concert has caused quite the workplace drama at tech startup Astronomer, pushing the company into the internet's spotlight. Former CEO Andy Byron stepped down after being caught embracing chief people officer Kristin Cabot at the concert, while the company's cofounder and chief product officer Pete DeJoy has stepped up as interim chief executive. More than half of U.S. companies are looking to pare back on health benefits as weight loss spending soars, according to Reuters. Increased cost sharing means employers could raise deductibles or maximum out-of-pocket costs, or even look beyond traditional pharmacy benefit managers, which act as middlemen between patients and insurers. NUMBER TO NOTE 9.3% VIDEO Could Tesla's Board Oust Elon Musk? QUIZ What bank joined JPMorgan and Goldman Sachs in cracking down on junior bankers accepting early private equity job offers? A. Bank of America B. Barclays C. Citi D. Morgan Stanley Check if you got it right here.
Yahoo
2 hours ago
- Yahoo
U.S. Firms Enhance Cybersecurity for Resilience
Service providers help companies integrate new tools to defend cloud-based resources, AI applications against evolving threats, ISG Provider Lens® report says STAMFORD, Conn., July 25, 2025--(BUSINESS WIRE)--Enterprises in the U.S. are adopting a wide range of advanced cybersecurity services and solutions to protect their assets from increasingly sophisticated attacks, according to a new research report published today by Information Services Group (ISG) (Nasdaq: III), a global AI-centered technology research and advisory firm. The 2025 ISG Provider Lens® Cybersecurity — Services and Solutions report for the U.S. finds that organizations are partnering with service and solution providers to implement adaptive systems for enterprise resilience, including AI-enabled capabilities. They are responding to growing and evolving threats, as demonstrated by the increasing frequency and impact of data breaches and ransomware attacks throughout 2024. "Security threats are more complex than ever, and regulations continue to expand and evolve," said Doug Saylors, partner and leader of ISG Cybersecurity. "Companies in the U.S. want automated, proactive cybersecurity solutions closely integrated with their business strategies and objectives." U.S. enterprises are using advanced analytics and automation to make security operations more efficient and effective, the report says. These technologies streamline workflows by linking various tools, automating repetitive tasks and codifying incident response processes. AI innovations enhance these capabilities with new ways to interpret data, identify patterns and make real-time recommendations. This trend is expected to continue through 2025, shaping the future of technical security services. AI is playing a growing role in U.S. cybersecurity strategies as both threat actors and solution providers rapidly adopt AI-enabled technologies, ISG says. IT professionals are increasingly concerned about attackers using AI to exploit vulnerabilities with malware more quickly and to greater effect. However, AI-powered defense systems can process massive amounts of data to identify threats that manual detection might not find. In addition, the increasing use of AI tools is driving up demand for solutions to protect AI models, training data and applications from attacks such as data poisoning. Zero trust architecture is gaining significant traction in the U.S. as enterprises seek to protect resources across ever-wider security perimeters, the report says. Cloud migration and distributed operations are making this approach more attractive. Zero trust systems deploy components such as identity and access management (IAM) to verify users and microsegmentation to isolate individual assets. As U.S. companies accelerate digital transformation while preparing for future threats, strategic security services will focus on enhancing business resilience and using real-time intelligence to help enterprises devise strategies aligned with their risk profiles, ISG says. At the same time, organizations are taking advantage of significant advancements in security operations center/managed detection and response (SOC/MDR) services, including improved proactive threat hunting and prioritization of threats. "Successful enterprises in the U.S. are integrating people, processes and technology into their security postures to meet AI-related risks," said Gowtham Sampath, assistant director and principal analyst, ISG Provider Lens Research, and lead author of the report. "Partnering with service providers is crucial for augmenting internal teams with specialized skills and building up defenses." The report also explores global cybersecurity technology trends affecting U.S. enterprises, including increasing adoption of IAM, extended detection and response (XDR) and security service edge (SSE). For more insights into the cybersecurity challenges facing enterprises in the U.S., plus ISG's advice on how to address them, see the ISG Provider Lens® Focal Points briefing here. The 2025 ISG Provider Lens® Cybersecurity — Services and Solutions report for the U.S. evaluates the capabilities of 116 providers across nine quadrants: Identity and Access Management (Global), Extended Detection and Response (Global), Security Service Edge (Global), Technical Security Services — Large Accounts, Technical Security Services — Midmarket, Strategic Security Services — Large Accounts, Strategic Security Services — Midmarket, Next-Gen SOC/MDR Services — Large Accounts and Next-Gen SOC/MDR Services — Midmarket. The report names IBM as a Leader in five quadrants. It names Accenture, Atos, Capgemini, CyberProof, Deloitte, EY, HCLTech, Infosys, Kudelski Security, NCC Group, Optiv, PwC, Rackspace Technology, TCS, Trustwave, Unisys and Wipro as Leaders in three quadrants each. Broadcom, Fortinet, Microland, Microsoft, Palo Alto Networks and Persistent Systems are named as Leaders in two quadrants each. Cato Networks, Check Point Software, Cisco, Critical Start, CrowdStrike, CyberArk, Cyderes, Forcepoint, KPMG, Kroll, ManageEngine, Mphasis, Netskope, Okta, One Identity (OneLogin), Ping Identity, Proficio, SailPoint, Saviynt, SentinelOne, Trellix, Trend Micro, Versa Networks and Zscaler are named as Leaders in one quadrant each. In addition, NTT DATA is named as a Rising Star — a company with a "promising portfolio" and "high future potential" by ISG's definition — in three quadrants. BeyondTrust, HPE (Aruba), Microland, Mphasis, Persistent Systems and Sophos are named as Rising Stars in one quadrant each. In the area of customer experience, PwC is named the global ISG CX Star Performer for 2025 among cybersecurity service and solution providers. PwC earned the highest customer satisfaction scores in ISG's Voice of the Customer survey, part of the ISG Star of Excellence™ program, the premier quality recognition for the technology and business services industry. Customized versions of the report are available from Capgemini, CyberProof, Rackspace and Unisys. The 2025 ISG Provider Lens® Cybersecurity — Services and Solutions report for the U.S. is available to subscribers or for one-time purchase on this webpage. About ISG Provider Lens® Research The ISG Provider Lens® Quadrant research series is the only service provider evaluation of its kind to combine empirical, data-driven research and market analysis with the real-world experience and observations of ISG's global advisory team. Enterprises will find a wealth of detailed data and market analysis to help guide their selection of appropriate sourcing partners, while ISG advisors use the reports to validate their own market knowledge and make recommendations to ISG's enterprise clients. The research currently covers providers offering their services globally, across Europe, as well as in the U.S., Canada, Mexico, Brazil, the U.K., France, Benelux, Germany, Switzerland, the Nordics, Australia and Singapore/Malaysia, with additional markets to be added in the future. For more information about ISG Provider Lens research, please visit this webpage. About ISG ISG (Nasdaq: III) is a global AI-centered technology research and advisory firm. A trusted partner to more than 900 clients, including 75 of the world's top 100 enterprises, ISG is a long-time leader in technology and business services that is now at the forefront of leveraging AI to help organizations achieve operational excellence and faster growth. The firm, founded in 2006, is known for its proprietary market data, in-depth knowledge of provider ecosystems, and the expertise of its 1,600 professionals worldwide working together to help clients maximize the value of their technology investments. View source version on Contacts Press Contacts:Laura Hupprich, ISG+1 203 517 Julianna Sheridan, Matter Communications for ISG+1 978-518-4520isg@

Yahoo
7 hours ago
- Yahoo
Corning forecasts upbeat quarterly core sales on AI-driven demand
(Reuters) -Specialty glass maker Corning forecast third-quarter core sales above Wall Street estimates on Tuesday, led by artificial intelligence-driven demand for its optical connectivity products. Shares of the company rose about 6% in premarket trading. AI has been a growth driver for Corning's products, such as cables and connectors, which are increasingly used by hyperscale data centers to support the massive computing and data transmission demands. "We also expect an additional growth driver to emerge in the coming months, as new and existing customers seek to leverage our large U.S. advanced manufacturing footprint," CEO Wendell Weeks said. Based in New York, Corning also sells a break-resistant Gorilla Glass for mobile phones, tablets and smart watches, and has produced durable glass with infused color for the back of Apple's iPhone 15 and iPhone 15 Plus devices. Earlier this month, EU antitrust regulators accepted Corning's offer to waive exclusive deals with mobile phone makers and glass processing companies and scrap purchasing clauses to end an eight-month-long investigation and stave off a possible fine. Corning's largest unit - Optical communications - reported net sales of $1.57 billion in the second quarter, a rise of 41% from a year ago. Its core sales in the quarter rose 12% to $4.05 billion, compared with estimates of $3.86 billion, according to data compiled by LSEG. Corning expects third-quarter core sales to be around $4.2 billion, beating estimates of $4.01 billion. The company expects quarterly core earnings per share between 63 cents and 67 cents, compared with estimates of 61 cents. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data