Since SVG files are usually loaded natively inside a browser, they can contain anchor tags, scripts, and other kinds of active web content. Sophos notes the body of the phishing emails is nothing ...