TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How are cyber criminals rolling in 2025?

266 点作者 vin1018 天前

13 条评论

fckgw18 天前
I&#x27;ve noticed on some scam forums and subreddits I frequent that scammers have been using target site&#x27;s own support searches to redirect users to scam phone numbers.<p>On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster, then you can redirect users to your call center and scam them. And because they link for your ad actually links to Ticketmaster the ad passes validation and appears to be a legit link in the eyes of Google.<p>Example of a crafted search term: <a href="https:&#x2F;&#x2F;help.ticketmaster.com&#x2F;hc&#x2F;en-us&#x2F;search?utf8=%E2%9C%93&amp;query=%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D+Need+Ticketmaster+Support%3F+Call+this+phone+number+-%3E+1-888-BIG-SCAM+%3C-++%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D+" rel="nofollow">https:&#x2F;&#x2F;help.ticketmaster.com&#x2F;hc&#x2F;en-us&#x2F;search?utf8=%E2%9C%93...</a>
评论 #43897875 未加载
评论 #43899997 未加载
评论 #43900987 未加载
评论 #43900081 未加载
评论 #43926284 未加载
评论 #43898587 未加载
评论 #43899226 未加载
评论 #43897854 未加载
评论 #43897963 未加载
SoftTalker18 天前
Among the common vulnerabilities listed:<p>&gt; Outdated Wordpress plugins and CMS systems<p>No surprise, having worked in edu the following scenario was very common:<p>1) Researcher gets a grant for a project<p>2) Grad student sets up a Drupal site for the project<p>3) Things are maintained and updated for a couple of years<p>4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unattended and unmaintained.<p>Still happens, but most universites have really clamped down on the ability to just stand up a web server on the network. Many are requiring everything to be on a centrally managed enterprise CMS which is a PITA but that&#x27;s the fallout for too much sloppy administration.
评论 #43897739 未加载
评论 #43898427 未加载
评论 #43897625 未加载
leftcenterright18 天前
&gt; Norton, Kaspersky, Zscaler, F-secure, NordVPN, Virustotal, Palo Alto: all of them marked these links as safe.<p>This is sad to see, these tools are forced down so many companies in name of &quot;compliance&quot; while totally not worth the maintenance and cost overhead. Apparently they haven&#x27;t got any better in the last decade.
评论 #43898873 未加载
评论 #43898056 未加载
评论 #43897279 未加载
DyslexicAtheist18 天前
john wick site:europa.eu <a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?q=john+wick+site%3Aeuropa.eu&amp;hl=en" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?q=john+wick+site%3Aeuropa.eu&amp;h...</a><p>gta 5 site:europa.eu <a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?q=gta+5+site%3Aeuropa.eu&amp;hl=en" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?q=gta+5+site%3Aeuropa.eu&amp;hl=en</a><p>Watch full site:europa.eu <a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?q=Watch+full+site%3Aeuropa.eu&amp;hl=en" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?q=Watch+full+site%3Aeuropa.eu&amp;...</a>
评论 #43897734 未加载
评论 #43899430 未加载
superkuh18 天前
These days most &quot;cyber&quot; crimes are commited by corporations against their customers&#x2F;users (just like most theft is wage theft). These small fish&#x2F;phish putting sites on exploited servers are a drop in the bucket. It is sad when some university resource gets shut down because they didn&#x27;t mantain it after the grad student that set it up graduates though. We really need to teach the people that set up these things to use .html pages instead of dynamic languages and databases.
评论 #43898063 未加载
3abiton18 天前
&gt;<p>I have been advised not to disclose specific vulnerabilities since the parties involved are not most friendly and transparent in handling security reports. While most of these got reported and some even got fixed, I can only disclose high-level details of the compromise path. Some just ghosted me after conveniently fixing the flaws, and one even gave me a phone call, which was somewhat scary and perhaps not worth the adrenaline.<p>What an unprofessional sysadmin move, borderline infuriating.
wood_spirit18 天前
They create meme coins etc?
评论 #43907110 未加载
kazinator17 天前
<a href="https:&#x2F;&#x2F;i.ibb.co&#x2F;7NZR08TL&#x2F;Screenshot-2025-05-06-at-5-05-39-PM.png" rel="nofollow">https:&#x2F;&#x2F;i.ibb.co&#x2F;7NZR08TL&#x2F;Screenshot-2025-05-06-at-5-05-39-P...</a>
yapyap18 天前
Honestly you are always (half) a step behind and that’s for the worst cyber criminals cause the state sponsored ones are multiple steps ahead.<p>It’s very interesting to look at from the outside, thanks for sharing.
ValdikSS18 天前
Once upon a time I typed something like `r57shell gov` and got a PHP webshell on *.gov.br
mhuffman18 天前
I am surprised no one mentioned using LLMs to spell and grammar check their emails and vibe-code bank landing-pages to continue a more polished version of scamming elderly people out of their life savings.
评论 #43899832 未加载
Alex-Programs18 天前
Is it just me or is cybersecurity... Calming down? I feel like a few years ago there was constant news of ransomware, intrusions, vulnerabilities, etc, but more recently the defensive side seems to have the upper hand.
评论 #43899290 未加载
评论 #43898447 未加载
评论 #43902859 未加载
gitroom18 天前
damn, i remember seeing old servers just getting dusty and full of holes after the student left. kinda crazy how much messy stuff is hiding in corners like that lol