325
Threat actors exploited Windows 0-day for more than a year before Microsoft fixed it
(arstechnica.com)
This is a most excellent place for technology news and articles.
The fact that Windows hasn't solved the "fake extension" scam is wild. You can't make people not click stuff, obviously. But you absolutely could identify double extensions clearly intended to confuse people and give some kind of "this isn't a PDF" warning.
I don't think it would help. Even without the extension it would still say:
not-malicious.pdf (Application)
We are trained to see file extensions and understand them, but the masses aren't. There is a column that translates the hidden extension into its corresponding type already.
My computer-iliterate dad is on Debian XFCE since 2 years now. The first year, he thought it was the new Windows. File extensions didn't bother him in the slightest.
I don't think extensions are a "bother" at all. It's just a different way to show the info.