Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Top Metaverse investments plunge – What’s going on?

    TL;DR Breakdown Prices of metaverse lands have drastically fallen between 2022 and 2023, following a booming bull market in NFTs. As of May 24, 2023, metaverse land costs range from 0.37 to 1.09 ETH, with the most expensive being Otherdeeds by Yuga Labs and the cheapest in Voxels. In the peak of the NFT bull market, metaverse lands cost up to 7.50 ETH, with Otherdeeds being the most expensive, followed by Somnium, Decentraland, The Sandbox, and Voxels. The world of virtual real estate has been in a spin, with metaverse land prices plummeting in the past year. This comes in the wake of a roaring bull market in non-fungible tokens (NFTs) that saw prices of digital land parcels soar to unprecedented levels. Now, however, the once high-flying investments have hit a significant rough patch, with prices of metaverse land dropping drastically between 2022 and 2023. Sinking values in the Metaverse As of May 24, 2023, the cost of owning a plot in the metaverse ranges from 0.37 to 1.09 ETH, with prices differing among various virtual real estate projects. Interestingly,…

    Article 2023年5月30日
  • Liquidation Looms: DeFi Ecosystem Faces Another Bailout with Venus Protocol’s $30M Event

    TL;DR Breakdown BNB’s price dipped below the liquidation threshold, leading the BNB core team to liquidate $30 million in USDT debt, seizing $33 million of BNB collateral. Despite the recent liquidation, the position’s health remains at risk, with potential further liquidations if BNB’s price drops to around $210.8. Description The decentralized finance (DeFi) world is again on edge, grappling with the repercussions of a significant liquidation event. The Binance Smart Chain’s (BSC) Venus Protocol is the latest platform to take unprecedented steps to mitigate systemic risks. This comes in the wake of a series of events that have shaken the DeFi community’s confidence. Contents … Read more The decentralized finance (DeFi) world is again on edge, grappling with the repercussions of a significant liquidation event. The Binance Smart Chain’s (BSC) Venus Protocol is the latest platform to take unprecedented steps to mitigate systemic risks. This comes in the wake of a series of events that have shaken the DeFi community’s confidence. Contents hide 1 A Quarter-Billion Dollar Position and a Notorious Hack 2 BNB Core Team Steps In Averting a…

    Article 2023年8月20日
  • Liquity price analysis: LQTY recovers to $1.25 following a sudden dip

    TL;DR Breakdown The Liquity price analysis is bullish today. Resistance for LQTY is present at $1.41. Support for LQTY is present at $1.12. The current Liquity price analysis points towards an upward trend in the cryptocurrency today. Despite encountering bearish resistance in the previous day, the bulls have successfully propelled the price to $1.25 within the last four hours. The presence of a green candlestick signifies a renewed increase in the coin’s value following a sudden dip. Hourly price predictions align with these market trends for LQTY/USD, showcasing upward movement over the past four hours after a brief crash towards $0.93 that occurred within a five-minute timeframe. However, the token swiftly recovered from this dip. It’s important to note that resistance lies at the $1.41 level, potentially reintroducing selling pressure. LQTY/USD 1-day price chart: A resurgence of bullish sentiment sparks renewed market activity In the realm of one-day Liquity price analysis, positive developments emerge for cryptocurrency buyers, as the price exhibits significant recovery throughout the day. At the time of writing, the coin is trading at $1.25, and there are…

    Article 2023年5月26日
  • Colorado Division of Motor Vehicles (DMV) partners with PayPal to accept crypto as a form of payment

    TL;DR Breakdown The Colorado Division of Motor Vehicles (DMV) has become the first government agency in the state to accept cryptocurrency as payment for online services like driver’s licenses and vehicle registrations. To enable this, the DMV has partnered with PayPal, which will handle the cryptocurrency transactions by converting digital assets into dollars. A service fee will be applied for using this payment method. Description The Colorado Division of Motor Vehicles (DMV) has started accepting cryptocurrency as a form of payment for its online services. This initiative makes the DMV the first government agency in the state to embrace digital assets for financial transactions. PayPal crypto enables payments for driver’s licenses and vehicle registrations To facilitate this new payment option, … Read more The Colorado Division of Motor Vehicles (DMV) has started accepting cryptocurrency as a form of payment for its online services. This initiative makes the DMV the first government agency in the state to embrace digital assets for financial transactions. PayPal crypto enables payments for driver’s licenses and vehicle registrations To facilitate this new payment option, the DMV…

    Article 2023年9月2日
  • Mercedes-Benz to integrate ChatGPT into its vehicles

    TL;DR Breakdown Mercedes-Benz has announced that it will infuse ChatGPT’s chatbot into its vehicles. The company says it will enable data protection and consumer engagement as the core of the design. German automaker Mercedes-Benz has announced plans to introduce OpenAI’s ChatGPT chatbot into its vehicles through a beta program for the Mercedes-Benz User Experience (MBUX) feature. This integration will enable AI-driven voice commands and provide additional functionality to enhance the user experience for Mercedes-Benz owners. The beta program will commence on June 16 and run for three months, exclusively targeting the United States market. Mercedes-Benz to test the feature in a beta program Mercedes-Benz will leverage the Microsoft Azure OpenAI Service, which was launched by Microsoft in March, to bring the popular ChatGPT chatbot to its cars. The MBUX voice assistant, featuring the well-known “Hey Mercedes” feature, was initially introduced in 2018 on the A-Class vehicles. To participate in the beta program, drivers simply need to inquire about it through their vehicles. The voice commands for the AI are performed directly through the car’s interface, allowing drivers to interact seamlessly…

    Article 2023年6月19日
TOP