Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Vladimir Putin condemns the weaponization of the US dollar

    TL;DR Breakdown Russian President Vladimir Putin has condemned the weaponization of the US dollar due to the harm it has done to the NDB. Promoting national currencies and energy loans. Description In the recent Russia-Africa Summit held in Saint Petersburg, Russian President Vladimir Putin and Dilma Rousseff, President of the New Development Bank (NDB), engaged in discussions about the challenges faced by the bank in the current international arena. Vladimir Putin expressed concerns over the weaponization of the dollar and its impact on the global economy, … Read more In the recent Russia-Africa Summit held in Saint Petersburg, Russian President Vladimir Putin and Dilma Rousseff, President of the New Development Bank (NDB), engaged in discussions about the challenges faced by the bank in the current international arena. Vladimir Putin expressed concerns over the weaponization of the dollar and its impact on the global economy, which has complicated the NDB’s task of growing and developing its role on the world stage. Vladimir Putin emphasizes the need to develop the NDB In the meeting, Vladimir Putin emphasized the need for concerted efforts…

    Article 2023年7月30日
  • Supercharged Liquidity Pools on Osmosis: Empowering Liquidity Providers for Enhanced Rewards

    TL;DR Breakdown Osmosis approves supercharged liquidity pools, enabling liquidity providers to concentrate assets within specific ranges and gain higher rewards based on actual liquidity usage. A gradual migration process will be followed, starting with the deployment of a DAI/OSMO supercharged pool and subsequent migrations of classic curve pools. Description In a significant development for the Osmosis ecosystem, the community has successfully authorized the deployment of supercharged liquidity pools. These pools aim to provide liquidity providers with the ability to concentrate their assets within specific ranges, offering an opportunity to maximize rewards. The introduction of concentrated liquidity pools marks a shift towards a more efficient … Read more In a significant development for the Osmosis ecosystem, the community has successfully authorized the deployment of supercharged liquidity pools. These pools aim to provide liquidity providers with the ability to concentrate their assets within specific ranges, offering an opportunity to maximize rewards. The introduction of concentrated liquidity pools marks a shift towards a more efficient allocation of incentives based on actual liquidity usage, as opposed to the previous system of evenly distributed rewards….

    Article 2023年6月23日
  • SEC Chair Gensler asserts, “we don’t need more digital currency” as agency sues Coinbase and Binance

    TL;DR Breakdown SEC Chair Gary Gensler asserts there is no need for more digital currency amidst lawsuits against Binance and Coinbase for allegedly operating unregistered securities exchanges. Gensler defends the SEC’s legal position and draws parallels between the cases against Binance’s CEO and FTX founder, highlighting the importance of compliance with securities regulations. The charges against Coinbase focus on violations of US securities laws, with the SEC alleging that the exchange operated as an unregistered national securities exchange, broker, and clearing agency. In an interview with CNBC, Securities and Exchange Commission (SEC) Chair Gary Gensler responded to criticism by denying that his approach was confusing the crypto industry. This comes as the SEC filed lawsuits against major cryptocurrency exchanges Binance and Coinbase for allegedly operating unregistered securities exchanges. Gensler also drew parallels between the case against Binance‘s CEO Changpeng “CZ” Zhao and the criminal case involving FTX founder Sam Bankman-Fried. Gensler emphasized that the U.S. doesn’t require additional digital currencies, stating, “We already have digital currency; it’s called the U.S. dollar.” Also, he argued that throughout history, economies and the…

    Article 2023年6月11日
  • Lido Finance reassures investors amid security flaw concerns in LDO token contract

    TL;DR Breakdown Lido Finance acknowledges a security flaw in its LDO token but assures tokens are secure. SlowMist identifies the flaw, which allows transactions without sufficient funds. Lido Finance argues the issue is common to all ERC-20 tokens. Description Ethereum staking protocol Lido Finance has publicly acknowledged a known security flaw in its LDO token contract. The announcement came in response to a September 10 post by blockchain security firm SlowMist, which highlighted the vulnerability that could potentially enable “fake deposit” attacks on cryptocurrency exchanges, Cryptopolitan reported.  Despite the concerns, Lido Finance reassured investors … Read more Ethereum staking protocol Lido Finance has publicly acknowledged a known security flaw in its LDO token contract. The announcement came in response to a September 10 post by blockchain security firm SlowMist, which highlighted the vulnerability that could potentially enable “fake deposit” attacks on cryptocurrency exchanges, Cryptopolitan reported.  Despite the concerns, Lido Finance reassured investors that both Lido DAO LDO and staked-Ether (stETH) tokens remain secure. Lido Finance counters SlowMist’s allegations SlowMist’s analysis revealed that the flaw in the LDO token contract allows…

    Article 2023年9月12日
  • MetaMask releases a new update on crypto tax

    TL;DR Breakdown MetaMask has sparked confusion in the crypto community after it updated its policy on crypto tax. The firm has refused to disclose any information to its users. MetaMask, a popular crypto wallet, has recently sparked confusion and surprise within the crypto community due to its new terms of conditions. The updated policy states that if users fail to pay taxes, MetaMask reserves the right to withhold funds from their wallets for tax departments. This move by MetaMask and its developer, ConsenSys, has raised concerns about the principles of decentralization and financial freedom that underpin cryptocurrencies. MetaMask sparks controversy with crypto tax policy According to the revised terms of service introduced by ConsenSys in April 2023, consumers are required to pay all taxes, government fees, and charges. The fees payable by users are considered exclusive of taxes, and MetaMask reserves the right to withhold taxes where necessary. This policy has drawn criticism from the crypto community, particularly because it goes against the core principle of decentralization and the idea of financial sovereignty. The crypto community swiftly took to Twitter…

    Article 2023年5月23日
TOP