logo
Delete Any Emails On Your Phone Or PC That Include These Images

Delete Any Emails On Your Phone Or PC That Include These Images

Forbes16-07-2025
These images are dangerous.
Here we go again. There's a fast growing threat in your inbox that's hard to detect — even for security software on your PC. This has 'seemingly come out of nowhere,' but you need to be aware. And it means deleting a raft of incoming emails.
The new warning comes courtesy of Ontinue, which says 'threat actors are increasingly leveraging Scalable Vector Graphics (SVG) files as a delivery vector for JavaScript-based redirect attacks.' Plenty of these images, 'commonly treated as harmless' contain 'embedded script elements' that lead to browser redirects. And that's a huge risk.
While these images might be .SVG attachments, as we have seen before, they could also be links to external images pulled into the email. And the campaign also relies on spoofed domains and email lures to trick users into opening and engaging.
VIPRE warns that 'up until this point, SVGs have been recognized by email security tools as generally benign image files, which is why attackers are now having so much success hiding their nefarious exploits in them.'
Looking at this latest warning, SlashNext's J Stephen Kowski told me 'when you open or preview these 'images,' they can secretly redirect your browser to dangerous websites without you knowing.' That means you need to be 'extra careful' with images.
Because the latest attacks leverage spoofed domains and senders to trick you, it isn't as easy as just avoiding emails from unknown senders. Instead, you should delete any email with an .SVG attachment unless you're expecting it. And you should allow your browser to block external images until you're certain of their origin.
Kowski says these emails will also likely be 'pushy about viewing the image right away,' and while 'your email provider's built-in security features, such as spam filtering and safe attachments, can help, they're not perfect against these newer tricks.'
Jason Soroko from Sectigo goes even further, warning security teams to 'treat every inbound SVG as a potential executable,' as the surge in such attacks continues.
The real threat though lies in user complacency. SVG attacks, VIPRE says, are now tussling with PDFs to become 'attackers' favorite attachments of choice.' These are only images, most users assume, and so no click-throughs, no harm.
Ontinue says 'the observed targets of this campaign fall into B2B Service Providers, including the ones handling valuable Corporate Data regularly, including Financial and Employee data, Utilities, Software-as-a-Service providers that are great social engineering targets as they expect to receive a high volume of emails.'
And the team warns 'this technique demonstrates how adversaries are shifting away from executable payloads and towards smuggling (HTML and now SVG) techniques. By embedding script logic into image formats and using trusted browser functions, the attack chain avoids triggering traditional behavioral or signature-based alerts.'
The emails containing the attachments or links will be simple, 'using a minimal format to avoid detection and provoke curiosity or interaction.' Hijacking poorly protected domains or spoofing others with special characters enhances the lure.
The advice is just as simple. If you're not expecting an email which includes image links or .SVG attachments, delete them from your inbox. 'This campaign highlights a creative pivot in attacker methodology,' the team says, 'using benign file formats to hide malicious logic and evade established detection controls.'
Which is another way of saying that you're your own best defense.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Pentagon Snub Rattles Cybersecurity Conference Circuit
Pentagon Snub Rattles Cybersecurity Conference Circuit

Wall Street Journal

time2 hours ago

  • Wall Street Journal

Pentagon Snub Rattles Cybersecurity Conference Circuit

A Pentagon move to pull its officials out of a policy think tank event is sending a chill across the cybersecurity trade-show circuit, where senior military and national security leaders often appear as keynote speakers and panelists. By barring its officials from participating in cybersecurity conferences, the Defense Department would imperil critical threat-intelligence sharing between public and private cybersecurity experts, among other issues, event organizers, vendors and attendees say.

What Happened to BlackBerry (BB) Stock This Year?
What Happened to BlackBerry (BB) Stock This Year?

Yahoo

time5 hours ago

  • Yahoo

What Happened to BlackBerry (BB) Stock This Year?

Key Points BlackBerry stock has gone nowhere over the past year. The company is relying on its QNX and SecuSmart divisions to drive its near-term growth. The stock is not as cheap as it appears to be given its growth potential. 10 stocks we like better than BlackBerry › BlackBerry (NYSE: BB) was once synonymous with smartphones, but it lost that booming market to the Apple iPhone and Android-powered devices. It eventually stopped producing phones entirely and reinvented itself as an Internet of Things (IoT) and cybersecurity software provider, but it's still struggling to expand in those saturated markets. The stock has traded flat in 2025 as the S&P 500 is up 8% year to date. Let's see why BlackBerry is trailing the broad market this year and where it might be headed over the next 12 months. BlackBerry's two core growth engines Most of BlackBerry's recent growth has been driven by two acquisitions. First, it acquired QNX, the world's most popular embedded operating system (OS) for vehicles, back in 2010. That acquisition helped it profit from the secular growth of the connected and driverless vehicle markets. In 2023, it launched BlackBerry IVY, a cloud-based connected-vehicle platform which was built on QNX and co-developed with Amazon Web Services. BlackBerry rebranded its entire IoT business as QNX earlier this year, and it expects more automotive design wins to drive its results long-term. In fiscal 2025 (which ended this past February), the QNX segment's revenue rose 10% year over year and accounted for 44% of BlackBerry's top line. Second, BlackBerry acquired the cybersecurity company Cylance in 2019 for $1.4 billion. That acquisition was aimed at strengthening its cybersecurity software business, but it faced stiff competition from bigger and faster-growing competitors like Palo Alto Networks and CrowdStrike. In February, it sold Cylance's endpoint security assets to Arctic Wolf for $160 million in cash and equity. In fiscal 2025, BlackBerry's revenue from its secured communications segment (which houses its cybersecurity services, SecuSmart secure messaging and call services, and other security tools) dipped 4% year over year but still accounted for 51% of its top line. BlackBerry previously leveraged its patents to generate high-margin royalties and licensing fees, but it sold most of that portfolio over the past three years to raise fresh cash. As a result, its licensing revenue plunged 90% in fiscal 2025 and only accounted for 5% of its top line. What will happen to BlackBerry over the next year? BlackBerry expects to generate $508 million to $538 million in revenue in fiscal 2026, which would represent a 2% decline at the midpoint. This includes a 10% to 14% hit to secured communications revenue stemming from the Cylance sale, though the company continues to gain more SecuSmart customers. For QNX, management is guiding for 10% full-year growth at the midpoint of its $250 million to $270 million range. On the bottom line, adjusted earnings before interest, taxes, depreciation, and amortization (EBITDA) should range between a 14% decline and 3% growth. For fiscal 2027, however, analysts expect revenue and adjusted EBITDA to rise 9% and 18%, respectively, as QNX and SecuSmart gain new customers. Is it the right time to buy BlackBerry stock? With an enterprise value of $2.2 billion, BlackBerry isn't much of a bargain at four times this year's sales. It also trades at 27 times forward adjusted EBITDA. Insiders have been net sellers of the stock over the past 12 months too. If BlackBerry manages to meet analysts' expectations and still trades at 27 times its forward adjusted EBITDA by the beginning of fiscal 2027, its shares could rise 16% over the next 12 months. If either of its two main segments stumble, however, its valuation multiples would likely contract, driving the stock lower. That's why I don't think BlackBerry stock is worth buying yet. Should you buy stock in BlackBerry right now? Before you buy stock in BlackBerry, consider this: The Motley Fool Stock Advisor analyst team just identified what they believe are the for investors to buy now… and BlackBerry wasn't one of them. The 10 stocks that made the cut could produce monster returns in the coming years. Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you'd have $624,823!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you'd have $1,064,820!* Now, it's worth noting Stock Advisor's total average return is 1,019% — a market-crushing outperformance compared to 178% for the S&P 500. Don't miss out on the latest top 10 list, available when you join Stock Advisor. See the 10 stocks » *Stock Advisor returns as of July 29, 2025 Leo Sun has positions in Amazon and Apple. The Motley Fool has positions in and recommends Amazon, Apple, and CrowdStrike. The Motley Fool recommends BlackBerry and Palo Alto Networks. The Motley Fool has a disclosure policy. What Happened to BlackBerry (BB) Stock This Year? was originally published by The Motley Fool

New York City is "most certainly prepared" for a potential cyberattack, officials say
New York City is "most certainly prepared" for a potential cyberattack, officials say

CBS News

time12 hours ago

  • CBS News

New York City is "most certainly prepared" for a potential cyberattack, officials say

Escalating tensions between the United States and Iran is leading to growing concerns about the potential for a cyberattack, including here in New York City. New York is on a heightened level of security after the U.S. military struck three sites in Iran back in June, but Chief Technology Officer Matthew Fraser says the city is "most certainly prepared." "Whenever they look at spreading terror or whenever they look at targeting something, needless to say, New York comes very high on the list," Fraser said. Officials emphasize there are no credible threats, but Fraser says the city's Office of Technology and Innovation, including its Cyber Command Unit, is monitoring over 100 billion cybersecurity incidents a week, compared 90 billion last year. Most incidents are vetted through artificial intelligence. Fraser walked CBS News New York's Jennifer Bisram through the city's joint security operations center in Downtown Brooklyn, where threats against critical networks that keep lights on, water running and transportation systems humming across the city are detected, deferred and deterred around the clock. "In real time, we have people that are looking and responding to those types of alerts. We have people that are building packages to go out and hunt to find the latest threats that may exist," Fraser said. The Office of Technology and Innovation says every quarter, it's training new students and producing cybersecurity experts through its NYC Cyber Academy. CBS News New York was also given access to New York City Office of Emergency Management's watch command center. Commissioner Zach Iscol says last year's IT outage is an example of how the city's emergency partners came together and used backup systems to keep the city running. "One of the things we saw last year with the CrowdStrike incident is unlike a lot of other places around the county, New York City was able to deliver all essential services, and a lot of that credit goes to the coup team here," he said. City officials say threats from the sky, however, are a concern. "Drones is one of those newer emerging threats, and so there are responses for that. We depend heavily on our federal partners here in the city," Iscol said. While the ability to take a drone down in the city is limited, there's a safety level of protection that can be put around sensitive and secure facilities to safeguard against hackers. In the meantime, cybersecurity specialists say New Yorkers can avoid a data breach by using strong passwords, multi-factor authentications and keeping all software systems updated.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store