{"id":5038,"date":"2024-03-01T13:00:11","date_gmt":"2024-03-01T20:00:11","guid":{"rendered":"https:\/\/www.whitefirdesign.com\/blog\/?p=5038"},"modified":"2024-03-01T12:05:53","modified_gmt":"2024-03-01T19:05:53","slug":"github-apps-and-linkedin-pulse-being-abused-by-web-spammers","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2024\/03\/01\/github-apps-and-linkedin-pulse-being-abused-by-web-spammers\/","title":{"rendered":"GitHub Apps and LinkedIn Pulse Being Abused by Web Spammers"},"content":{"rendered":"<p>In the last few days, we have been looking at various aspects of a web spam campaign. We have found that, among other things,<a href=\"https:\/\/www.whitefirdesign.com\/blog\/2024\/02\/28\/spammers-still-abusing-drupal-webform-module-to-put-spam-pdfs-and-pages-on-websites\/\"> websites from various major universities<\/a> have <a title=\"Brigham Young University CDN Being Abused by Web Spammers\" href=\"https:\/\/www.whitefirdesign.com\/blog\/2024\/03\/01\/brigham-young-university-cdn-being-abused-by-web-spammers\/\">been impacted by this<\/a>. We also found that GitHub and LinkedIn, which are both owned by Microsoft, have been impacted by this and they don&#8217;t seem to be doing a great job of catching that.<\/p>\n<p>One aspect of this involves GitHub Apps. Here is one example of spam pages on there:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/github-apps-web-spam.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5044\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/github-apps-web-spam.png\" alt=\"\" width=\"1179\" height=\"669\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/github-apps-web-spam.png 1179w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/github-apps-web-spam-300x170.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/github-apps-web-spam-768x436.png 768w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/github-apps-web-spam-1024x581.png 1024w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<p>That, in turn, links to a page on LinkedIn Pulse:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linkedin-web-spam.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5045\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linkedin-web-spam.png\" alt=\"\" width=\"807\" height=\"658\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linkedin-web-spam.png 807w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linkedin-web-spam-300x245.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linkedin-web-spam-768x626.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>You can see that was published a week ago and is still up.<\/p>\n<p>What is going on with the account that was posted through is unclear. It is listed as a financial services company, but the rest of the description isn&#8217;t in line with that:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5046\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-1.png\" alt=\"\" width=\"762\" height=\"476\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-1.png 762w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-1-300x187.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>There is another account for what appears to be the same entity that seems more credible, as among other things, it lists them in the music industry<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5047\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-2.png\" alt=\"\" width=\"964\" height=\"1544\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-2.png 964w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-2-187x300.png 187w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-2-768x1230.png 768w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2024\/03\/linked-in-profile-2-639x1024.png 639w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the last few days, we have been looking at various aspects of a web spam campaign. We have found that, among other things, websites from various major universities have been impacted by this. We also found that GitHub and LinkedIn, which are both owned by Microsoft, have been impacted by this and they don&#8217;t &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2024\/03\/01\/github-apps-and-linkedin-pulse-being-abused-by-web-spammers\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;GitHub Apps and LinkedIn Pulse Being Abused by Web Spammers&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-5038","post","type-post","status-publish","format-standard","hentry","category-spam"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/5038","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=5038"}],"version-history":[{"count":3,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/5038\/revisions"}],"predecessor-version":[{"id":5049,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/5038\/revisions\/5049"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=5038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=5038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=5038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}