Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Kalshi has probed and flagged 400+ suspicious trades YTD, more than 2x the number it investigated in all of 2025; Polymarket has seen a similar uptick (Anirban Sen/Reuters)
    • Today’s NYT Mini Crossword Answers for May 16
    • Huawei car headlights project movies and games in full color
    • UK EdTech Multiverse lands €60 million funding round at €1.8 billion valuation
    • Greg Brockman Officially Takes Control of OpenAI’s Products in Latest Shake-Up
    • Seoul-based WIRobotics, which develops wearable and humanoid robots and is collaborating with Nvidia and AWS, raised a ~$68M Series B led by JB Investment (Lee Jaewoon/The Elec)
    • Today’s NYT Connections: Sports Edition Hints, Answers for May 16 #600
    • Proxy-Pointer RAG — Structure-Aware Document Comparison at Enterprise Scale
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Saturday, May 16
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Adult sites are stashing exploit code inside racy .svg files
    News

    Adult sites are stashing exploit code inside racy .svg files

    Editor Times FeaturedBy Editor Times FeaturedAugust 25, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link


    The obfuscated code inside an .svg file downloaded from one of many porn websites.

    Credit score:
    Malwarebytes

    The obfuscated code inside an .svg file downloaded from one of many porn websites.


    Credit score:

    Malwarebytes

    As soon as decoded, the script causes the browser to obtain a series of extra obfuscated JavaScript. The ultimate payload, a recognized malicious script known as Trojan.JS.Likejack, induces the browser to love a specified Fb put up so long as a person has their account open.

    “This Trojan, additionally written in Javascript, silently clicks a ‘Like’ button for a Fb web page with out the person’s information or consent, on this case the grownup posts we discovered above,” Malwarebytes researcher Pieter Arntz wrote. “The person should be logged in on Fb for this to work, however we all know many individuals maintain Fb open for simple entry.”

    Malicious makes use of of the .svg format have been documented earlier than. In 2023, pro-Russian hackers used an .svg tag to take advantage of a cross-site scripting bug in Roundcube, a server software that was utilized by greater than 1,000 webmail providers and tens of millions of their finish customers. In June, researchers documented a phishing assault that used an .svg file to open a pretend Microsoft login display screen with the goal’s e mail tackle already crammed in.

    Arntz stated that Malwarebytes has recognized dozens of porn websites, all operating on the WordPress content material administration system, which are abusing the .svg information like this for hijacking likes. Fb frequently shuts down accounts that interact in these kinds of abuse. The scofflaws frequently return utilizing new profiles.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Kalshi has probed and flagged 400+ suspicious trades YTD, more than 2x the number it investigated in all of 2025; Polymarket has seen a similar uptick (Anirban Sen/Reuters)

    May 16, 2026

    Seoul-based WIRobotics, which develops wearable and humanoid robots and is collaborating with Nvidia and AWS, raised a ~$68M Series B led by JB Investment (Lee Jaewoon/The Elec)

    May 16, 2026

    UK gambling harms research center begins nationwide

    May 15, 2026

    SpaceX aims to make its IPO prospectus public by next week, targeting a June 12 listing on Nasdaq, driven by a faster-than-expected SEC review (Reuters)

    May 15, 2026

    Wisconsin restricts insider trading activities on prediction markets

    May 15, 2026

    Oklahoma overrides veto to enact online sweepstakes gambling

    May 15, 2026

    Comments are closed.

    Editors Picks

    Kalshi has probed and flagged 400+ suspicious trades YTD, more than 2x the number it investigated in all of 2025; Polymarket has seen a similar uptick (Anirban Sen/Reuters)

    May 16, 2026

    Today’s NYT Mini Crossword Answers for May 16

    May 16, 2026

    Huawei car headlights project movies and games in full color

    May 16, 2026

    UK EdTech Multiverse lands €60 million funding round at €1.8 billion valuation

    May 16, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Is She Really Mad at Me? Maybe ChatGPT Knows

    May 20, 2025

    Terahertz Radar: A New Era in Auto Safety

    November 22, 2025

    GM sells your driving data to insurers, FTC steps in to stop it

    January 18, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.