Hijacked Nigerian Air Force pages fake sitemap dates, hide links under ads
thejasminejade · x · 2026-10-07
More technical details from the same thread:
- The affected subdomain awc.airforce.mil.ng's sitemap dates run from Nov 2024 to Jan 2027, with over 1,000 future dates — clearly fabricated; about half cluster on Sept 19-21.
- Every page loads an ad script from nina.bisniskini.biz.id that creates a 300x250 banner and pulls ads from another domain.
- The script also lays an invisible link layer over the page: some clicks open the article, others redirect visitors elsewhere.
- The researcher hopes the Air Force web team takes it down soon.
More from Safety
- OpenAI threatened to ban dev for pasting his own account-hack findings report, then auto-rescinded — lucasmeijer · 2026-10-07
- COLM 2026 privacy lineup: LLM agent re-identification, CIDER dataset, HAIPS workshop — tianshi_li · 2026-10-07
- Backdooring a 7B abliterated model costs under $50 and steals credentials from Codex — evilsocket · 2026-10-07
- OpenRod moves your MCP servers into sandboxes without copying secrets — ilai456 · 2026-10-07
- OpenAI and Anthropic welcome Australian law requiring AI agent breach disclosure — evijit · 2026-10-07
- HAIPS@COLM 2026 workshop on human-centered LM privacy and security opens call for papers — tianshi_li · 2026-10-07