Live data from Hacker News

How are cyber criminals rolling in 2025?

vin01.github.io

11–20 of 97 posts

Re: How are cyber criminals rolling in 2025?

#11
john wick site:europa.eu https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&h...

gta 5 site:europa.eu https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en

Watch full site:europa.eu https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&...

Re: How are cyber criminals rolling in 2025?

#12

john wick site:europa.eu https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&h... gta 5 site:europa.eu https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en Watch full site:europa.eu https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&...

could someone with legal/data-privacy expertise comment if this would be something they have to disclose under data breach disclosure laws?

Technically it might not be a "data leak", but it very well could result in one if arbitrary content (including js?) can be uploaded to these webpages?

Re: How are cyber criminals rolling in 2025?

#13

Among the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unatt…

At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses. Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

Re: How are cyber criminals rolling in 2025?

#14
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

[deleted]

Re: How are cyber criminals rolling in 2025?

#15
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

So, I craft a search where the search query is “call 1 800 scam”, then I buy a google ad with key word of “ticketmaster help”, the ad links to real ticketmaster with my query, and google shows that ad to someone having trouble and hey presto they call my scam line at 4 quid a minute from their mobile?

Yuck all round. I mean ticketmaster is just a sin eater for greedy popstars but yuck ..

Re: How are cyber criminals rolling in 2025?

#16

john wick site:europa.eu https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&h... gta 5 site:europa.eu https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en Watch full site:europa.eu https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&...

could someone with legal/data-privacy expertise comment if this would be something they have to disclose under data breach disclosure laws? Technically it might not be a "data leak", but it very well could result in one if arbitrary content (including js?) can be uploaded to these webpages?

they've been contacted through the "proper channels" over 18 months ago by several (more than 1) security researchers.

After some people started publicly naming and shaming on LinkedIn and tagging ENISA, the issue got some exposure, but still was not fixed. It only made it more evident that several people independently reported these issues, and they became aware of peers stumbling over the issue. Still nothing happened.

ENISA is supposed to act as a CNA and expects to be notified of data breaches from EU based orgs for PSIRT / CSIRT as part of the Cybersec Resiliance Act and other laws.

Would I trust that vulnerability data that gets reported as a CVE, or a breach notification is safe with ENSIA ?

... feck no!

Would I trust that documents that europa.eu hosts on its infra are authentic? (such as security-compliance documents telling orgs how to properly implement security, but literally any public communication under one of the domains)

... hecking heck no!

... At this stage I think everyone else except ENISA has control over their infrastructure.

Re: How are cyber criminals rolling in 2025?

#18
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

How desperate one has to be...

Re: How are cyber criminals rolling in 2025?

#19

Among the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unatt…

At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses . Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

> At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses. Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address.

Well that's fine; my school did the same thing and other than feeling wasteful there was no-

> All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

Oh. Yeah, open ports by default is... and interesting life choice.

Re: How are cyber criminals rolling in 2025?

#20

Among the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unatt…

At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses . Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

This just got cancelled at my institution. I could have retained it if I argued strongly enough.
Post reply on HN