File Attack Deep Dives
2 parts, in reading order.
Part 1
How File-Based Attacks Land: A Detection Engineer's Field Guide
A practical taxonomy of how malware and phishing arrive as files, why classic controls miss them, and how detection should think.
Part 2File Attack Deep Dives, Part 2: HTML Smuggling
How attackers assemble malware inside the browser with Blob URLs, and the URL and script tells that catch it.