1 min read

Twitter Spam Campaign Exploits CNN Vulnerability

Bianca STANESCU

June 07, 2013

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
Twitter Spam Campaign Exploits CNN Vulnerability

A campaign that takes advantage of vulnerabilities on the CNN website is flooding Twitter users with diet spam, according to eHackingNews. Cyber-criminals exploit the open redirect flaw to post spam messages that look like they’re coming from the reputable news organization.

Twitter Spam Campaign Exploits CNN Vulnerability“The diet porgram you told us about yesterday is soo good!”, spammers tweeted, then redirected users to a malicious website.

“I love myself even more after I started your diet porgram [link]”, another message reads. “Yahoo made an article about how amazing your new diet program is!! You look amazing.”

Spammers made grammar mistakes to avoid antispam filters and gained users` trust by associating the scam with a renowned company. Because the request goes to the CNN website, the URL filtering doesn`t block access to the malicious websites.

According to eHackingNews, a similar security vulnerability might also be exploited in Yahoo. This is not the first time CNN is targeted by cyber criminals. Three years ago, scammers managed to exploit the same flaw in “ads.cnn.com”.

Open redirects are applications that take a parameter and redirect users to its value without validation. Exploiting vulnerabilities in open redirects allows cyber-criminals to make users visit their own website, without noticing.

Due to its increasing popularity, Twitter is targeted more often by cyber-criminals and social engineers. Recently, a popular hashtag on the micro-blogging platform started to be abused for phishing and identity theft.

After a series of high-profile hackings, the company announced two-factor authentication in May, including mobile phones in the verification processes.

tags


Author



Right now

Top posts

The Holiday Guide to Tech Support: Fixing the Family Computer

The Holiday Guide to Tech Support: Fixing the Family Computer

November 24, 2021

2 min read
Bitdefender Celebrates 20 Years of Cybersecurity Leadership

Bitdefender Celebrates 20 Years of Cybersecurity Leadership

November 04, 2021

3 min read
Bitdefender Study Reveals How Consumers Like (and Dislike) Managing Passwords

Bitdefender Study Reveals How Consumers Like (and Dislike) Managing Passwords

October 26, 2021

3 min read
What are drive-by download attacks and how do you prevent them?

What are drive-by download attacks and how do you prevent them?

October 25, 2021

2 min read
Criminals Can't Wait to Add Your IoT Device to Their DDoS Networks

Criminals Can't Wait to Add Your IoT Device to Their DDoS Networks

October 22, 2021

2 min read
Six in 10 Consumers Faced a Cyber Threat in 2021, New Bitdefender Study Reveals

Six in 10 Consumers Faced a Cyber Threat in 2021, New Bitdefender Study Reveals

October 20, 2021

3 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Chrome 96 Gets 22 More Security Fixes with New Incremental Update Chrome 96 Gets 22 More Security Fixes with New Incremental Update
Filip TRUȚĂ

December 08, 2021

1 min read
Most Employees Believe Passwords Affect Their Productivity, Research Finds Most Employees Believe Passwords Affect Their Productivity, Research Finds
Silviu STAHIE

December 06, 2021

1 min read
US State Department iPhones Infected with Pegasus Spyware – Report US State Department iPhones Infected with Pegasus Spyware – Report
Filip TRUȚĂ

December 06, 2021

2 min read