Case Study: Microsoft Limits Inline SVG Images in Outlook to Combat Phishing and Malware
📊Incident Overview
Microsoft is updating Outlook to stop displaying inline SVG images in an effort to mitigate security risks associated with phishing and malware. While SVG attachments will still be supported, the change aims to reduce the potential for cross-site scripting (XSS) attacks.
📚Lessons Learned
Lesson 1
Lesson 2
Lesson 2