home.social

#fakesites — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fakesites, aggregated by home.social.

  1. ⚽ ALERT: Scammers are targeting World Cup fans with fake streams, spoofed FIFA pages & ticket traps. Protect yourself—know which domains to avoid. Read the full scam watch guide: mediaboxent.com/world-cup-free

    #WorldCup #CyberSecurity #ScamAlert #OnlineSafety #Football #FakeSites #TicketScam #Phishing #FanSafety #ProtectYourself

  2. Phishing Trends: February 2026 – April 2026

    We observed decreases in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services. But not all good news. Other stories:

    Weed Prevention Fails in .GARDEN

    Small TLDs Under Siege

    Spaceship Takes Off… But Not in a Good Way

    Cloudflare Is King of a Reshuffled Top 20 Mountain

    Ball of Confusion?

    lnkd.in/e8bigV_P

    #phishing #fraud #cybercrime #fakesites #cybersecurity

  3. Phishing Trends: February 2026 – April 2026

    We observed decreases in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services. But not all good news. Other stories:

    Weed Prevention Fails in .GARDEN

    Small TLDs Under Siege

    Spaceship Takes Off… But Not in a Good Way

    Cloudflare Is King of a Reshuffled Top 20 Mountain

    Ball of Confusion?

    lnkd.in/e8bigV_P

    #phishing #fraud #cybercrime #fakesites #cybersecurity

  4. Phishing Trends: February 2026 – April 2026

    We observed decreases in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services. But not all good news. Other stories:

    Weed Prevention Fails in .GARDEN

    Small TLDs Under Siege

    Spaceship Takes Off… But Not in a Good Way

    Cloudflare Is King of a Reshuffled Top 20 Mountain

    Ball of Confusion?

    lnkd.in/e8bigV_P

    #phishing #fraud #cybercrime #fakesites #cybersecurity

  5. Phishing Trends: February 2026 – April 2026

    We observed decreases in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services. But not all good news. Other stories:

    Weed Prevention Fails in .GARDEN

    Small TLDs Under Siege

    Spaceship Takes Off… But Not in a Good Way

    Cloudflare Is King of a Reshuffled Top 20 Mountain

    Ball of Confusion?

    lnkd.in/e8bigV_P

    #phishing #fraud #cybercrime #fakesites #cybersecurity

  6. Phishing Trends: February 2026 – April 2026

    We observed decreases in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services. But not all good news. Other stories:

    Weed Prevention Fails in .GARDEN

    Small TLDs Under Siege

    Spaceship Takes Off… But Not in a Good Way

    Cloudflare Is King of a Reshuffled Top 20 Mountain

    Ball of Confusion?

    lnkd.in/e8bigV_P

    #phishing #fraud #cybercrime #fakesites #cybersecurity

  7. @jeroengui : I very much appreciate your work, but, as a bullet proof proxy service, #CloudflareIsEvil - they're complicit to cybercrime.

    Cloudflare warns for malware/phishing for a specific *URL*, not the domain.

    A minor change in the adds (or a forwarding site if that is what these scammers use) would bypass Cloudflare's crap measure.

    I never saw a malware/phishing warning while opening:

    https:⧸⧸keepass-xc.com/index.php

    Note: I understand that blocking https:⧸⧸sites.google.com for a single malicious page would be problematic, but that's rather due to the fact that Google Sites sucks.

    @keepassxc

    #BigTechIsEvil #Malware #Phishing #FakeSites

  8. @jeroengui : I very much appreciate your work, but, as a bullet proof proxy service, #CloudflareIsEvil - they're complicit to cybercrime.

    Cloudflare warns for malware/phishing for a specific *URL*, not the domain.

    A minor change in the adds (or a forwarding site if that is what these scammers use) would bypass Cloudflare's crap measure.

    I never saw a malware/phishing warning while opening:

    https:⧸⧸keepass-xc.com/index.php

    Note: I understand that blocking https:⧸⧸sites.google.com for a single malicious page would be problematic, but that's rather due to the fact that Google Sites sucks.

    @keepassxc

    #BigTechIsEvil #Malware #Phishing #FakeSites

  9. @jeroengui : I very much appreciate your work, but, as a bullet proof proxy service, #CloudflareIsEvil - they're complicit to cybercrime.

    Cloudflare warns for malware/phishing for a specific *URL*, not the domain.

    A minor change in the adds (or a forwarding site if that is what these scammers use) would bypass Cloudflare's crap measure.

    I never saw a malware/phishing warning while opening:

    https:⧸⧸keepass-xc.com/index.php

    Note: I understand that blocking https:⧸⧸sites.google.com for a single malicious page would be problematic, but that's rather due to the fact that Google Sites sucks.

    @keepassxc

    #BigTechIsEvil #Malware #Phishing #FakeSites

  10. @jeroengui : I very much appreciate your work, but, as a bullet proof proxy service, #CloudflareIsEvil - they're complicit to cybercrime.

    Cloudflare warns for malware/phishing for a specific *URL*, not the domain.

    A minor change in the adds (or a forwarding site if that is what these scammers use) would bypass Cloudflare's crap measure.

    I never saw a malware/phishing warning while opening:

    https:⧸⧸keepass-xc.com/index.php

    Note: I understand that blocking https:⧸⧸sites.google.com for a single malicious page would be problematic, but that's rather due to the fact that Google Sites sucks.

    @keepassxc

    #BigTechIsEvil #Malware #Phishing #FakeSites

  11. ICYMI: DuckDuckGo expands browser scam protection against fake sites: DuckDuckGo's browser now guards against investment scams and fake tech support alongside existing phishing defenses. ppc.land/duckduckgo-expands-br #DuckDuckGo #CyberSecurity #ScamProtection #OnlineSafety #FakeSites

  12. ICYMI: DuckDuckGo expands browser scam protection against fake sites: DuckDuckGo's browser now guards against investment scams and fake tech support alongside existing phishing defenses. ppc.land/duckduckgo-expands-br #DuckDuckGo #CyberSecurity #ScamProtection #OnlineSafety #FakeSites

  13. @robert_a : Clouflare is primarily a CDN company.

    CDN proxy servers
    ———————————
    Cloudflare owns proxy servers in most worldwide networking centers, typically one near you:

    you <--> proxy server <--> real server

    Their proxy servers (like Fastly) typically cache static comtent.

    Advantages:
    ———————
    • Faster speed for you.

    • DDoS protection for the actual servers.

    Disadvantages for you:
    —————————————
    • Your browser has an E2EE connection to a Cloudflare proxy server, NOT to the actual server. You have no idea regarding the security of the connection between the Cloudflare proxy server and the actual server, nor how well Cloudflare checks the authenticity of the remote server (even http, a self signed or a revoked certificate might be used without you knowing it).

    • You don't know the server's IP address (and therefor you don't know which party hosts it in which country - which may be Russia or China) allowing malicioius servers to "hide" behind Cloudflare IP addresses.

    • You can't block Cloudflare IP adresses without experiencing a lot of false positives (one Cloudflare IP adress is used to proxy thousands of servers). Cloudflare IP-addresses for a server often change, making it harder to block anything. This makes CDN's the perfect hiding place for malicious websites.

    • Cloudflare has access to HUGE amounts of -unencrypted- internet traffic, which is an ENORMOUS privacy risk.

    • As a US company, Cloudflare has to deal with FISA section 702. Three-letter agencies love Cloudflare.

    Hosting
    —————
    In addition, Cloudflare hosts mostly free *.pages.dev and *.workers.dev sites which are abused *A LOT* for malicious purposes. One year ago (it didn't stop, on the contrary): trustwave.com/en-us/resources/

    Root cause of rising cybercrime stats
    —————————————————————
    Cybercriminals can, mostly anonymously, obtain domain names and hire server space. And the get https certificates for free (*). That would not be a big problem if browsers would distinguish between cheap junk on the web and reputable web sites (they don't because that would cause big tech to earn less).

    (*) If websites like the following *look* real, how can one possibly know that they're fake? (a few of loads of examples):

    • https:⁄⁄formula1-tickets.com
    • https:⁄⁄paris24tickets.net
    • https:⁄⁄robbiewilliams-tickets.com
    • https:⁄⁄page.facebook-guidelines.com
    • https:⁄⁄adobe-pdf-online.com
    • https:⁄⁄accounts.hetzner.com.do

    Internet is criminalizing more every day.

    @GossiTheDog @campuscodi

    #CloudFlare #Fastly #InfoSec #Cybercrime #FakeSites

  14. @robert_a : Clouflare is primarily a CDN company.

    CDN proxy servers
    ———————————
    Cloudflare owns proxy servers in most worldwide networking centers, typically one near you:

    you <--> proxy server <--> real server

    Their proxy servers (like Fastly) typically cache static comtent.

    Advantages:
    ———————
    • Faster speed for you.

    • DDoS protection for the actual servers.

    Disadvantages for you:
    —————————————
    • Your browser has an E2EE connection to a Cloudflare proxy server, NOT to the actual server. You have no idea regarding the security of the connection between the Cloudflare proxy server and the actual server, nor how well Cloudflare checks the authenticity of the remote server (even http, a self signed or a revoked certificate might be used without you knowing it).

    • You don't know the server's IP address (and therefor you don't know which party hosts it in which country - which may be Russia or China) allowing malicioius servers to "hide" behind Cloudflare IP addresses.

    • You can't block Cloudflare IP adresses without experiencing a lot of false positives (one Cloudflare IP adress is used to proxy thousands of servers). Cloudflare IP-addresses for a server often change, making it harder to block anything. This makes CDN's the perfect hiding place for malicious websites.

    • Cloudflare has access to HUGE amounts of -unencrypted- internet traffic, which is an ENORMOUS privacy risk.

    • As a US company, Cloudflare has to deal with FISA section 702. Three-letter agencies love Cloudflare.

    Hosting
    —————
    In addition, Cloudflare hosts mostly free *.pages.dev and *.workers.dev sites which are abused *A LOT* for malicious purposes. One year ago (it didn't stop, on the contrary): trustwave.com/en-us/resources/

    Root cause of rising cybercrime stats
    —————————————————————
    Cybercriminals can, mostly anonymously, obtain domain names and hire server space. And the get https certificates for free (*). That would not be a big problem if browsers would distinguish between cheap junk on the web and reputable web sites (they don't because that would cause big tech to earn less).

    (*) If websites like the following *look* real, how can one possibly know that they're fake? (a few of loads of examples):

    • https:⁄⁄formula1-tickets.com
    • https:⁄⁄paris24tickets.net
    • https:⁄⁄robbiewilliams-tickets.com
    • https:⁄⁄page.facebook-guidelines.com
    • https:⁄⁄adobe-pdf-online.com
    • https:⁄⁄accounts.hetzner.com.do

    Internet is criminalizing more every day.

    @GossiTheDog @campuscodi

    #CloudFlare #Fastly #InfoSec #Cybercrime #FakeSites

  15. @bohofromthegetgo
    We forget, what is your position on CloudFlare? A lot of sites are "fake Russian" and actually go through #CloudFlare.

    A good way to find #fakeSites or sites that allow #massSurviellance, is to use Ctrl+Shift+E in TorBrowser. CloudFlare sites have "cf-ray" in their HTTP responses, #Amazon have "amz" or "AmazonS3". The #AkamaiGhost and Azure are centralised scams.

    Lots of #malware as a service on the #legacyInternet.

    #amAZONS3 #cDNs #corporateDictatorshipNetworks #useI2P