Over 1 in 20 emails are malicious, warns internet giant Cloudflare

cointelegraphPublicado a 2025-12-16Actualizado a 2025-12-16

Resumen

According to Cloudflare's 2025 year-in-review report, over 5.6% of global email traffic was malicious, meaning more than one in twenty emails contained harmful content. This figure surged to nearly 10% in November. Malicious emails aim to steal credentials, data, or money, with deceptive links being the most common threat category at 52%. Identity deception followed at 38%. The report highlights that crypto investors are particularly at risk, as phishing attacks have grown more complex and damaging. Additionally, highly abused top-level domains include “.christmas,” “.lol,” and “.forum.” Other studies support these findings, noting that a quarter of HTML attachments are malicious and email remains a primary attack vector.

More than 5% of all emails sent worldwide contain malicious content, according to internet infrastructure giant Cloudflare.

The web security giant revealed that an aggregate of 5.6% of global email traffic analyzed by the firm over the past year was found to be malicious. This equates to more than one in every twenty emails containing harmful content.

In November, that figure surged to almost one in ten, nearly double the average for the year, it found.

Malicious emails include those that can cause harm, such as the theft of credentials, data, or money, Cloudflare explained in its 2025 year-in-review report.

The findings are particularly relevant to crypto investors, as phishing attacks targeting crypto traders, investors, and executives have increased in complexity and surged in recent months.

Crypto phishing links can be especially damaging. Once a victim falls for one of these malicious links or sends cryptocurrency to a scammer, there’s usually no way back.

Malicious emails surged to 9.7% in November. Source: Cloudflare

Deceptive links dominate threat categories

More than half of these malicious emails, or 52%, contained a deceptive link, which was the highest threat category, it reported.

Identity deception was the second-highest at 38%, up from 35% in 2024, as attackers impersonated trusted individuals using spoofed domains, similar-looking domains, or display name tricks.

Related: Email auto-reply vulnerability allows hackers to mine cryptocurrency

Cloudflare also revealed that the most abused top-level domain (TLD) extension was “.christmas,” with 92.7% malicious emails and 7.1% spam originating from this domain type.

Other highly abused domain names included “.lol,” “.forum,” “.help,” “.best” and “.click.”

Deceptive links were the highest threat category among malicious emails. Source: Cloudflare

A quarter of HTML attachments are malicious

Earlier this year, researchers at cybersecurity company Barracuda analyzed 670 million emails that were malicious or unwanted spam.

They discovered that email remains the most common attack vector for cyber threats, with malicious attachments and links being used to distribute malware, launch phishing campaigns, and exploit vulnerabilities.

As many as one in four emails were unwanted spam, a quarter of all HTML attachments were malicious, and 12% of malicious PDF attachments were Bitcoin scams, they reported.

In November, Hornet Security reported that email was a “consistent delivery vector” for cyberattacks in 2025, with malware-laden emails surging by 131% year-over-year.

Magazine: Do Kwon sentenced to 15 years, Bitcoin’s ‘choppy dance’: Hodler’s Digest

Lecturas Relacionadas

Bernstein's 97-Page Report Decoded: The Battle for AI Data Center Connectivity, Who Will Be the True Winner by 2026?

Bernstein's 97-page report analyzes the AI data center connectivity landscape. It argues that the bottleneck is shifting from raw compute (GPU) to the systems connecting GPUs, crucial for cluster efficiency. Copper and optical interconnects are not in a simple replacement cycle but will coexist long-term, with copper dominating short-distance "scale-up" connections and optics favored for longer "scale-out" scenarios. While Co-Packaged Optics (CPO) is the long-term direction for power and cost savings, its widespread adoption faces manufacturing and reliability hurdles, with mass deployment unlikely before 2028. Transitional technologies like Linear Pluggable Optics (LPO) and Near-Packaged Optics (NPO) are seen as near-term leaders. A key insight is that CPO will fundamentally reshape the value chain, shifting profits from traditional optical module suppliers towards chip designers (e.g., NVIDIA, Broadcom), advanced packaging (e.g., TSMC), and system integrators. For 2026, the report highlights more immediate and certain investment opportunities in the essential "infrastructure" enabling this connectivity shift. This includes upgrades for PCBs, ABF substrates, and CCLa driven by new AI server/switch platforms, alongside demand for 1.6T optical modules, LPO/NPO, and the testing/validation equipment required for future CPO scale-up.

marsbitHace 10 min(s)

Bernstein's 97-Page Report Decoded: The Battle for AI Data Center Connectivity, Who Will Be the True Winner by 2026?

marsbitHace 10 min(s)

Understanding the New Economic Model of Tokenization

Understanding the New Token Economics Model The commercialization of AI applications is evolving from selling software and subscriptions to selling token call capacity. Tokens, the fundamental unit of information processing for large language models (LLMs), have become the basis for API billing and consumption. With call volumes exploding, tokens themselves are now being traded—procured, routed, split, and resold—forming a new intermediary market. This layer connects upstream LLM providers with downstream developers and enterprises, acting as a global wholesale-to-retail liquidity network. The rise of this business is fueled by a massive surge in China's daily token call volume—growing over a thousandfold from 100 billion in early 2024 to over 140 trillion by March 2026—and significant improvements in domestic LLM capabilities, which are now competitive globally. The core value of token distribution platforms extends beyond simple arbitrage. Key functions include aggregating multiple models (like GPT, Claude, and domestic models such as Kimi and DeepSeek) under a unified API, lowering network and payment barriers, and providing enterprise services like model selection, prompt engineering, and system integration. Profit models are diversifying: (1) resale margins; (2) technical premiums from proprietary inference acceleration (e.g., reducing costs to 1/10 of the industry standard); and (3) enterprise value-added services. High-consumption scenarios like marketing, short-form video, gaming, and e-commerce are primary drivers. Investment opportunities are seen in both companies with strong model capabilities (e.g., Alibaba, Tencent, MiniMax) and those with high-consumption client scenarios (e.g., marketing agencies with overseas reach). However, risks are significant: low entry barriers leading to intense competition, capital requirements and bad debt risks from advance payments, and dependency on policy changes from upstream LLM providers who control API pricing and access.

marsbitHace 32 min(s)

Understanding the New Economic Model of Tokenization

marsbitHace 32 min(s)

Farewell to the Copper Era: Understanding the Logic of the AI Silicon Photonics Industry Chain and Key US Stock Players

**Summary: The Era of Silicon Photonics and Key AI Infrastructure Stocks** The article delves into the transition from copper-based interconnects to silicon photonics (SiPh) as a critical enabler for next-generation AI data centers. It explains that copper faces fundamental physical limits—the bandwidth wall, density wall, and power wall—at high data rates (1.6T+), making a material shift essential. Silicon photonics, which integrates components like lasers, modulators, and detectors onto a silicon chip, offers a solution by leveraging mature CMOS manufacturing for cost-effective, high-volume production. A key challenge is that silicon itself is not an efficient light source, making Indium Phosphide (InP) lasers a critical and supply-constrained component. A major industry catalyst was NVIDIA's 2025 GTC announcement, declaring optical interconnects a "standard" from its Rubin platform onward, followed by strategic investments to secure the supply chain. The industry is structured in four key layers: 1. **Foundries:** TSMC leads with its COUPE platform, while Tower Semiconductor (specialized SiPh foundry) and GlobalFoundries are major players. 2. **Core Component Suppliers:** Lumentum is highlighted as the sole volume manufacturer of the crucial 200G/lane EML laser, with orders locked by NVIDIA through 2027. 3. **Module & System Manufacturers:** Coherent holds significant market share, with Chinese manufacturers like InnoLight also noted for scale. 4. **System Integrators:** NVIDIA, Broadcom, and Marvell dominate this layer, setting standards and integrating technology. The article identifies core public investment targets: **NVIDIA (NVDA)** as the ecosystem driver; **Broadcom (AVGO)** and **Marvell (MRVL)** in networking/switching chips; **Lumentum (LITE)** and **Coherent (COHR)** for critical components; and foundries **TSMC (TSM)** and **Tower Semiconductor (TSEM)**. Private companies Lightmatter and Ayar Labs are noted as key IPO candidates. The silicon photonics shift is driving a re-rating of company valuations, moving them from traditional telecom/industrial metrics to premium AI infrastructure multiples. The industry features high barriers to entry (e.g., multi-year lead times for InP laser capacity, complex 3D integration/thermal management, and lengthy customer qualification cycles), suggesting a "winner-takes-most" dynamic. Risks include dependence on hyperscaler capex cycles, potential technology disruption among competing optical approaches (LPO, CPO, OCS, Optical I/O), and a timeline where widespread CPO deployment may not occur until ~2028, with LPO serving as a transitional technology. The conclusion advises that betting on the overall industry trend may be safer than betting on any single company.

marsbitHace 1 hora(s)

Farewell to the Copper Era: Understanding the Logic of the AI Silicon Photonics Industry Chain and Key US Stock Players

marsbitHace 1 hora(s)

Deconstructing the Real Risks of DeFi Lending: Annual Loss Rate Only 0.03%

Deconstructing the true risks of DeFi lending reveals an annual loss rate of only 0.03% from hacks and exploits. Analysis of DeFi Llama data (excluding cross-chain bridge incidents) for EVM and Solana lending protocols shows that despite high historical attack frequency due to concentrated assets, the sector's security has matured significantly. Over the past year, non-cross-chain lending on these chains saw gross losses of $309M, with net losses after recoveries at $301M. Against a daily average TVL of $99.6B, this translates to a minimal annualized loss rate of approximately 0.03%. The Euler Finance case in 2023, where $197M was fully recovered, exemplifies improving asset recovery capabilities, which now account for roughly 20% of losses in this sector. Loss events follow a log-normal distribution: most are small-scale, with catastrophic losses being rare outliers. This pattern, combined with the massive scale of the total lending market, means single incidents rarely impact the broader ecosystem. It underscores the effectiveness of portfolio diversification and provides a basis for sustainable insurance models. The data indicates DeFi lending has entered a mature phase where risks are quantifiable, categorized, and manageable. The actual financial loss relative to the total capital deployed is extremely low, challenging prevailing narratives of systemic risk.

marsbitHace 1 hora(s)

Deconstructing the Real Risks of DeFi Lending: Annual Loss Rate Only 0.03%

marsbitHace 1 hora(s)

Trading

Spot
Futuros

Artículos destacados

Cómo comprar T

¡Bienvenido a HTX.com! Hemos hecho que comprar Threshold Network Token (T) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Threshold Network Token (T) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Threshold Network Token (T)Después de comprar tu Threshold Network Token (T), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Threshold Network Token (T)Tradear fácilmente con Threshold Network Token (T) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

590 Vistas totalesPublicado en 2024.12.10Actualizado en 2025.03.21

Cómo comprar T

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de T (T).

活动图片