7 ms·
How are cyber criminals rolling in 2025?
- SoftTalker 1y agoAmong the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unattended and unmaintained. Still happens, but most universites have really clamped down on the ability to just stand up a web server on the network. Many are requiring everything to be on a centrally managed enterprise CMS which is a PITA but that's the fallout for too much sloppy administration.
- kevin_thibedeau 1y agoThe low friction solution is to serve public_html from a home dir and direct users to generate static sites.
- notyourwork 1y agoYep, I remember having ssh access to production servers from a non-work machine at a well known university. We could also get external ips and connectivity without much supervision. Core security needs to be prioritized to avoid this from happening.
- semi-extrinsic 1y agoAt my old university ~15 years ago, all IPs of all computers were public IPV4 addresses. Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.
- fecal_henge 1y agoThis just got cancelled at my institution. I could have retained it if I argued strongly enough.
- yjftsjthsd-h 1y ago> At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses. Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. Well that's fine; my school did the same thing and other than feeling wasteful there was no- > All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture. Oh. Yeah, open ports by default is... and interesting life choice.
- morkalork 1y agoWhen you're living in the residences and there's a DC++ server running, it's pretty sweet. Ours had a whole 1.5TB of stuff on it!
- VoidWhisperer 1y agoWas this RIT by any chance?
- foobarian 1y agoAh the good old days of putting my head down at my desk lulled into a nap by the once-a-second sounds of ssh login attempt logs being written to the spinning rust drive...
- guappa 1y agoHow am I going to work from home if my computer at university is not recheable?
- DaSHacka 1y agoMy university does the same, except they understand the concept of "firewalls"
- rahimnathwani 1y agoOnly computers? At my old university even printers had public IP addresses.
- dehrmann 1y agoI used to have the public IP address of the computer in my dorm room memorized. It's been 20 years, and I still remember it started with 128.211.
- pjc50 1y agoI loved that era and it was hugely educational to me, but I can understand why it had to end.
- akeck 1y agoMIT and their /8?
- leftcenterright 1y ago> Norton, Kaspersky, Zscaler, F-secure, NordVPN, Virustotal, Palo Alto: all of them marked these links as safe. This is sad to see, these tools are forced down so many companies in name of "compliance" while totally not worth the maintenance and cost overhead. Apparently they haven't got any better in the last decade.
- charcircuit 1y agoI'm curious if the link inside the pdf would have been detected.
- vin10 1y agoIt is the same for nested links as well. They mostly have a chain of links, each one taking you to a new one with hop count ranging anywhere from 5 up to 10 or more.
- Muromec 1y agoWell, that's exactly the difference between complience and security
- markbeare 1y agoI work for a cybersecurity company, and I think that the method they used to check these links with the mentioned security companies was not a reflection of how they detect. I'm sure that many of these companies do not have these domains in their DBs of bad sites but if you were to run these products and then visit the site then heuristic detection would have likely flagged the sites.
- vin10 1y agoI would have expected at least Virustotal to flag them if that were the case. It does more than just looking up in a database of known malicious URLs and I think the reputation of the domains is the key factor here. https://www.virustotal.com/gui/url/6dd23e90ee436e1ff066725aa7ebcd5cfa238966b2b1712e856dffedbee0429f/details https://www.virustotal.com/gui/url/6dd23e90ee436e1ff066725aa... > BitDefender - government > Sophos - government > Forcepoint ThreatSeeker - government - https://docs.virustotal.com/docs/how-it-works https://docs.virustotal.com/docs/how-it-works
- superkuh 1y agoThese days most "cyber" crimes are commited by corporations against their customers/users (just like most theft is wage theft). These small fish/phish putting sites on exploited servers are a drop in the bucket. It is sad when some university resource gets shut down because they didn't mantain it after the grad student that set it up graduates though. We really need to teach the people that set up these things to use .html pages instead of dynamic languages and databases.
- neffy 1y agoSure. Corporations commit ransomware attacks all the time.
- gitroom 1y agodamn, i remember seeing old servers just getting dusty and full of holes after the student left. kinda crazy how much messy stuff is hiding in corners like that lol
- 3abiton 1y ago> I have been advised not to disclose specific vulnerabilities since the parties involved are not most friendly and transparent in handling security reports. While most of these got reported and some even got fixed, I can only disclose high-level details of the compromise path. Some just ghosted me after conveniently fixing the flaws, and one even gave me a phone call, which was somewhat scary and perhaps not worth the adrenaline. What an unprofessional sysadmin move, borderline infuriating.
- fckgw 1y agoI've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster, then you can redirect users to your call center and scam them. And because they link for your ad actually links to Ticketmaster the ad passes validation and appears to be a legit link in the eyes of Google. Example of a crafted search term: https://help.ticketmaster.com/hc/en-us/search?utf8=%E2%9C%93&query=%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D+Need+Ticketmaster+Support%3F+Call+this+phone+number+-%3E+1-888-BIG-SCAM+%3C-++%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D+ https://help.ticketmaster.com/hc/en-us/search?utf8=%E2%9C%93...
- pnw 1y agoFWIW I sent this to a friend on the dev team at Ticketmaster and they escalated it.
- araes 1y agoIts cool you at least attempted to do something with a bit of social connection at such a heavily targeted website. Having personal issues with Ticketmaster's pricing methods (causing many to probably never want to do anything that might help) is a different issue than the website being used as a source for redirecting calls to fake call centers. Since they escalated maybe something will get done. Ticketmaster would have a motivation, if large numbers fall prey to diverted call center scams it only makes their reputation flounder even worse. (...obvious joke here would be if the scammers actually offer better support, they're just trying to steal call center business)
- pnw 1y agoLooks like they already tweaked it so the result is less useful to the scammers.
- DyslexicAtheist 1y agojohn wick site:europa.eu https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&hl=en https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&h... gta 5 site:europa.eu https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en Watch full site:europa.eu https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&hl=en https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&...
- leftcenterright 1y agocould someone with legal/data-privacy expertise comment if this would be something they have to disclose under data breach disclosure laws? Technically it might not be a "data leak", but it very well could result in one if arbitrary content (including js?) can be uploaded to these webpages?
- DyslexicAtheist 1y agothey've been contacted through the "proper channels" over 18 months ago by several (more than 1) security researchers. After some people started publicly naming and shaming on LinkedIn and tagging ENISA, the issue got some exposure, but still was not fixed. It only made it more evident that several people independently reported these issues, and they became aware of peers stumbling over the issue. Still nothing happened. ENISA is supposed to act as a CNA and expects to be notified of data breaches from EU based orgs for PSIRT / CSIRT as part of the Cybersec Resiliance Act and other laws. Would I trust that vulnerability data that gets reported as a CVE, or a breach notification is safe with ENSIA ? ... feck no! Would I trust that documents that europa.eu hosts on its infra are authentic? (such as security-compliance documents telling orgs how to properly implement security, but literally any public communication under one of the domains) ... hecking heck no! ... At this stage I think everyone else except ENISA has control over their infrastructure.
- b0m 1y agoWhen clicked, all show: page not found So, fixed now?
- Alex-Programs 1y agoIs it just me or is cybersecurity... Calming down? I feel like a few years ago there was constant news of ransomware, intrusions, vulnerabilities, etc, but more recently the defensive side seems to have the upper hand.
- chelmzy 1y agoNot particularly. The only thing I have noticed in the past decade is the decline of the "American Hacker". Most groups are foreign but will partner with younger Americans for social engineering (ex. Scattered Spider). You just don't have people like Albert Gonzalez/Stephen Watt in America now. However, I suspect that many American hackers have shifted to targeting overseas countries that are not friendly with the US.
- alcover 1y ago> You just don't have people like Albert Gonzalez/Stephen Watt in America now I don't know what the state of big corps netsec is today but these guys had it somewhat easy. They got initial access through weak wifi then pivoted with SQL injects and such.
- candiddevmike 1y agoYou only hear about the offensive side winning when the company can't prevent it from leaking. Rest assured, the only thing "calming down" in cybersecurity is the nihilism that nothing involving a human will ever be secure.
- pjc50 1y agoThere's a lot of other stuff in the news.
- wood_spirit 1y agoThey create meme coins etc?
- tim333 1y agoIt's the way forward but not actually a crime. In the future we'll live by selling meme coins to each other while AIs do the actual work.
- deleted 1y ago[deleted]
- mhuffman 1y agoI am surprised no one mentioned using LLMs to spell and grammar check their emails and vibe-code bank landing-pages to continue a more polished version of scamming elderly people out of their life savings.
- curiousgal 1y agoThe misspellings/shitty grammar are on purpose.
- andrewflnr 1y agoI think the time for that has passed. The trend of the last few years has been scarily realistic phishing emails.
- mhuffman 1y agoI have heard that theory from some cybersecurity experts online but have never seen it substantiated in any way (by interviewing some scammers, for example) and frankly don't believe it. The misspellings and grammatical errors (used to?) continue on the fake sites that are created to steal credentials, and the excuses for most of the reasoning regarding emails do not hold there.
- 1dom 1y agoWhy wouldn't you believe it? It makes economic sense. The most expensive part for a scammer in any automated scam is the part which can't be automated, where a human has to get involved for e.g. a phonecall. Economically, the scammer wants to do everything they can to get rid of smart or diligent people who might be harder to scam at the expensive part. It feels like it would cost scammers to not have typos. Also, anecdotal, but the rise of autocorrect, spell checking and LLMs doesn't seem to have made any impact on the quality of spelling in my spam folder over the past 20 years.
- mhuffman 1y ago>Why wouldn't you believe it? Lots of reasons, but here are a few: 1. The misspellings and grammar issues (used to) continue beyond emails into the websites, etc. 2. The grammar issues, magically, seem to mimic the the same grammar differences between certain countries typical language constructions and those of standard American English 3. Check your spam folder right now if you have gmail. Where did this 4-D chess triage of illiterate potential dupes go? Spelling and grammar are suddenly almost perfect! Also, many of the older scams seem to be replaced with romance or family impersonation scams. >It makes economic sense. The most expensive part for a scammer in any automated scam is the part which can't be automated, where a human has to get involved for e.g. a phonecall. Perhaps you haven't heard, but this can also be automated as well, cheaply. Works particularly well on the elderly! >Economically, the scammer wants to do everything they can to get rid of smart or diligent people who might be harder to scam at the expensive part. It feels like it would cost scammers to not have typos. I think you are giving too much credit to the spammers. Economically, the easiest thing to do is to send out endless emails and wait for responses. Those people, regardless of diligence or literacy, are already self-selecting and you can let them talk to LLMs to winnow the rest. >Also, anecdotal, but the rise of autocorrect, spell checking and LLMs doesn't seem to have made any impact on the quality of spelling in my spam folder over the past 20 years. I agree ... up until the rise of LLM's. Now (outside of more use of emojis) it is very good.
- yapyap 1y agoHonestly you are always (half) a step behind and that’s for the worst cyber criminals cause the state sponsored ones are multiple steps ahead. It’s very interesting to look at from the outside, thanks for sharing.
- ValdikSS 1y agoOnce upon a time I typed something like `r57shell gov` and got a PHP webshell on *.gov.br
- kazinator 1y agohttps://i.ibb.co/7NZR08TL/Screenshot-2025-05-06-at-5-05-39-PM.png https://i.ibb.co/7NZR08TL/Screenshot-2025-05-06-at-5-05-39-P...