In 2025, phishing campaigns have adopted SVG files, which embed malicious JavaScript to redirect users to credential-harvesting sites. These versatile files evade traditional security measures, leading to a surge in attacks. Researchers note a significant increase in undetected malicious SVGs, utilizing complex obfuscation techniques that traditional analysis tools struggle to identify, revealing critical gaps in current cybersecurity defenses.

M&S: WFH staff locked out of systems amid cyber attack fallout – Retail Gazette
M&S employees working from home faced access issues to company systems due to the ongoing consequences of a cyber attack. The situation has disrupted operations,