Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Binance Tax Made Easy: Generate Your Tax Reports in Minutes

    TL;DR Breakdown Binance Tax supports up to 100,000 transactions on the Binance platform. In the future, you will be able to import transactions from other wallets and blockchains into Binance Tax. Note that Binance Tax currently does not support transactions related to certain Binance products, such as Futures and NFTs. You can add these transactions manually or take them up elsewhere on your tax return. Currently, each user can generate a Capital Gain Report, Income Gain Report, or a report of all their transactions in the 2022 tax year. For many crypto users, filing taxes can be a confusing, cumbersome, and time-consuming procedure, and Binance Tax aims to eliminate this financial obstacle. If you’re struggling to remain on top of your crypto taxes or simply want to expedite the process, be sure to check out Binance Tax, our recently released crypto tax calculator.  Globally, crypto taxation regulations are constantly evolving. Binance recognizes that, as a result, many of the users, including seasoned traders, find submitting their taxes to be difficult and time-consuming. The Binance Tax tool aids you in keeping…

    Article 2023年6月1日
  • Meta challenges Twitter with launch of new app

    TL;DR Breakdown Meta, the parent company of Instagram and Facebook, is set to launch Threads, a new app that poses a challenge to Twitter’s dominance in social media. Threads offers Twitter-like features, allowing users to publish text-based posts that can be liked, shared, and commented on. The launch of Threads comes as users express concerns over Twitter’s management under Elon Musk, prompting them to seek alternatives. Description Meta is set to launch Threads, its own rival to the popular social media platform Twitter. Expected to debut on Thursday, Threads will offer a text-based platform similar to Twitter, allowing users to publish posts, engage in discussions, and share content. The app will be closely linked to Meta’s photo-sharing platform, Instagram, enabling seamless portability … Read more Meta is set to launch Threads, its own rival to the popular social media platform Twitter. Expected to debut on Thursday, Threads will offer a text-based platform similar to Twitter, allowing users to publish posts, engage in discussions, and share content. The app will be closely linked to Meta’s photo-sharing platform, Instagram, enabling seamless portability…

    Article 2023年7月6日
  • Japan’s Prime Minister reiterates commitment to Web3 development amidst anticipation of Binance’s upcoming launch

    TL;DR Breakdown Japan’s Prime Minister reaffirmed his support for Web3 technology, signifying a trend toward blockchain and decentralized financial, supply chain, and governance breakthroughs. Binance, a renowned crypto exchange, announced its forthcoming launch in Japan, validating Japan’s crypto sector promotion efforts. Japan’s proactive Web3 policy might encourage other nations to follow suit, creating a more transparent, efficient, and inventive global digital economy.  Binance’s partnership with local regulators could enhance the crypto ecosystem for Japanese crypto enthusiasts. Description Japan’s Prime Minister has signaled a significant step toward adopting blockchain and decentralized technologies by reiterating the country’s commitment to Web3.  Additionally, Binance, one of the largest crypto exchanges in the world, has announced that it will soon launch in the country, solidifying the country’s status as a booming hub for Web3 innovation. Japan PM … Read more Japan’s Prime Minister has signaled a significant step toward adopting blockchain and decentralized technologies by reiterating the country’s commitment to Web3.  Additionally, Binance, one of the largest crypto exchanges in the world, has announced that it will soon launch in the country, solidifying the country’s…

    Article 2023年7月26日
  • Latest tech updates – Unstoppable Domains enables .eth messaging

    TL;DR Breakdown Reports have it that Unstoppable Domains has expanded its support for Unstoppable Messaging to include Ethereum with .eth. The new messaging integration relies on the independent extensible message transport protocol (XMTP) to entirely encrypt and send messages to recipients. Messages are encrypted end-to-end and stored on the decentralized network of XMTP to ensure solo and uncorrupted ownership. Description According to a team statement, Unstoppable Domains, a digital identity platform, is expanding its support for Unstoppable Messaging to include Ethereum. With this expansion, users with Ethereum Name Service (ENS) Domains will be able to engage in messaging across multiple platforms on XMTP, including applications such as Coinbase Wallet and Lens, by entering their wallet … Read more According to a team statement, Unstoppable Domains, a digital identity platform, is expanding its support for Unstoppable Messaging to include Ethereum. With this expansion, users with Ethereum Name Service (ENS) Domains will be able to engage in messaging across multiple platforms on XMTP, including applications such as Coinbase Wallet and Lens, by entering their wallet address or domain. Unstoppable Domains eth messaging…

    Article 2023年9月12日
  • China unviels white paper to foster web3 development

    TL;DR Breakdown China has released a roadmap for web3 development, investing 100 million yuan annually until 2025 in Beijing’s Chaoyang district. Recent signs, including a state-broadcasted Bitcoin segment, suggest a potential change in China’s cryptocurrency policy. The white paper’s release interestingly coincides with new cryptocurrency regulations in Hong Kong, hinting at evolving regional dynamics. China’s complicated relationship with the cryptocurrency industry has undergone a drastic twist. On May 27,  Beijing’s municipal government showcased a white paper heralding a commitment to accelerating the web3 industry’s growth. The paper spotlights various research areas in the web3 industry, taking in artificial intelligence (AI), content production tools, and XR interactive terminals. It also heralds the swift evolution of novel applications, such as digital populations and collections, while highlighting the need for adaptive policy reforms to surmount inherent developmental challenges. Zhongguancun Chaoyang Park, colloquially termed China’s Silicon Valley, will serve as the launch pad for these bold digital strides. The area’s Management Committee Director, Yang Hongfu, confirmed plans to commit no less than 100 million yuan (roughly $14 million) annually until 2025 to underpin this…

    Article 2023年5月30日
TOP