{"success":true,"data":{"id":"svg-attachment-phishing","label":"SVG attachment phishing — SVG files can contain executable JavaScript and full HTML phishing pages","description":"SVG files are XML documents that can embed full JavaScript via <script> tags and complete HTML pages via <foreignObject>. When a user opens an SVG attachment, their browser executes the embedded code — rendering a pixel-perfect credential harvest form. 2,825 SVG phishing emails documented in Q1 2025 alone (Hoxhunt). Legitimate email attachments are virtually never SVG; images use PNG/JPG and vector graphics use PDF.","tier":"danger","category":"phishing","isThin":false}}