Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Tensions soar as U.S. accuses Chinese minister of this

    TL;DR Breakdown U.S. officials claim Chinese Defense Minister Li Shangfu is under investigation. Li has not been publicly seen for over two weeks, fueling suspicions. His disappearance follows the ousting of two generals from the People’s Liberation Army Rocket Force and the removal of Qin Gang as Chinese foreign minister. Description As diplomatic temperatures between the U.S. and China continue to simmer, the focus has now sharply turned to Defense Minister Li Shangfu of China. Under intense scrutiny and amidst hushed whispers, the official narrative is being questioned by high-ranking insiders from the U.S. These revelations have cast long shadows over Beijing’s corridors of power, hinting … Read more As diplomatic temperatures between the U.S. and China continue to simmer, the focus has now sharply turned to Defense Minister Li Shangfu of China. Under intense scrutiny and amidst hushed whispers, the official narrative is being questioned by high-ranking insiders from the U.S. These revelations have cast long shadows over Beijing’s corridors of power, hinting at the increasing instability and disorder within China’s top military and foreign policy echelons. The Mysterious…

    Article 2023年9月15日
  • EU and Google join forces for voluntary AI pact

    TL;DR Breakdown The European Commission and Google are working to develop a voluntary AI pact before legislation comes into effect. This initiative aims to anticipate and prepare for AI’s potential societal and business impacts. EU Industry chief Thierry Breton has urged EU countries and lawmakers to finalize the proposed AI rules before the end of the year. In a remarkable leap towards defining the ever-changing landscape of Artificial Intelligence (AI), Google and the European Commission have announced plans to lay out a cooperative agreement for the emerging technology. This decision comes in light of the growing urgency for global oversight on AI’s societal and business implications. EU industry chief, Thierry Breton, took the initiative, meeting with Sundar Pichai, the CEO of Google and Alphabet, its parent company, to chart a path for an AI pact. This meeting sought to draw the blueprint for AI governance even before the regulatory frameworks become legally binding. Co-creation of AI pact: A voluntary undertaking Breton expressed the urgency of proactive measures, stating that there was no time to be complacent until AI regulation was…

    Article 2023年5月26日
  • Congressman: Banning CBDC vital for America’s future

    TL;DR Breakdown Congressman Warren Davidson opposes CBDCs, seeing them as threats to U.S. fintech. CBDCs and cryptocurrencies, like Bitcoin, are distinct and shouldn’t be conflated. Davidson’s main concern lies with the entities and influencers pushing for CBDCs. Description An outspoken critic on the move to introduce a central bank digital currency, U.S. Congressman Warren Davidson, once again steers the national conversation on the CBDC’s potential dangers and its profound implications for the nation’s fintech horizon. Contrary to popular belief, cryptocurrencies and CBDCs aren’t two sides of the same coin. Let’s take a deep … Read more An outspoken critic on the move to introduce a central bank digital currency, U.S. Congressman Warren Davidson, once again steers the national conversation on the CBDC’s potential dangers and its profound implications for the nation’s fintech horizon. Contrary to popular belief, cryptocurrencies and CBDCs aren’t two sides of the same coin. Let’s take a deep dive. CBDC: A Double-Edged Sword for American Fintech? Warren Davidson, a formidable figure on the House Financial Services Committee, doesn’t mince words when it comes to his stance on…

    Article 2023年8月17日
  • I asked AI to predict when Ether will hit its all-time high again, and I am shocked

    TL;DR Breakdown GPT-4, an advanced AI model, has made a bold prediction about Ethereum hitting a new all-time high by January 15, 2024. This prediction is based on ETH’s current bullish outlook, optimistic market sentiment, and developments such as the adoption of its Proof of Stake mechanism. The forecast has stirred excitement and anticipation in the crypto community, marking a significant potential milestone for the cryptocurrency. I recently engaged in an enlightening dialogue with an AI model, GPT-4, renowned for its analytical prowess. This encounter led to a startling prediction concerning Ethereum, the second-largest cryptocurrency by market capitalization. Decoding GPT-4’s Ethereum prediction Artificial Intelligence continues to disrupt various sectors, with the finance and cryptocurrency landscape being no exception. Renowned for its deep learning capabilities, GPT-4 has emerged as an insightful commentator in the digital currency ecosystem. Recently, I interacted with this cutting-edge model to discuss Ethereum’s outlook, given its current market status. At the time of our exchange, the largest altcoin was trading at $1,873, within a narrow price range. Engaging in an insightful dialogue, GPT-4 articulated a thought-provoking analysis…

    Article 2023年6月6日
  • BRICS bank urges global south financial system overhaul

    TL;DR Breakdown Dilma Rousseff, president of the BRICS bank, calls for a new financial structure catering to the Global South. The proposed structure aims to channel liquidity effectively and promote long-term investments in local currencies. Rousseff emphasized the strategic importance of multilateralism in the emerging multipolar world order. The BRICS bank has expanded its influence beyond the original bloc, incorporating Bangladesh, Egypt, UAE, and possibly Argentina and Honduras. Reform of the global financial structure has become a rallying cry for the New Development Bank (NDB), more commonly known as the BRICS bank. Dilma Rousseff, the bank’s president and former leader of Brazil, has passionately advocated for a financial framework that specifically addresses the unique needs of the Global South. A system tailored for the global south Drawing upon her international experience, Rousseff addressed a captive audience at the 14th Lujiazui Forum in Shanghai. She outlined her vision for the future: a financial structure better equipped to meet the challenges faced by nations outside the traditional spheres of power. The Global South, a term popularized by American writer Carl Oglesby to…

    Article 2023年6月17日
TOP