Security Fix is debuting “Nastygram,” a short, hopefully regular feature alerting readers about some of the latest, sneakier e-mail scams. Each report will include a graphic at the top like the one in this blog post, which explains what readers should do with these missives. One particularly insidious and persistent nastygram of late is a message that will look like it was sent by your company’s internal IT folks, and carries the subject “A new settings file for the [insert address of someone on your employer’s network]”. To increase the appearance of legitimacy, the message includes your company’s domain name throughout the message. The link embedded in the message is made to appear as though it will take you somewhere on your employer’s domain. In the old days, you could tell where a link was leading just by hovering over it with your mouse. Nowadays, the bad guys make