Security researchers have identified a new spam campaign on Twitterthat exploits an Open Redirect vulnerability that exists on a CNN subdomain.
The spam messages are mostly sent via compromised Twitter accounts and advertise a shady website offering work from home.
Spammers try to lure potential victims with messages such as: "Turn your million-dollar dream into reality", "Work from home and multiply your income comfortably and pleasantly", "The fastest and easiest way to work online", etc.
When users click on the links in the messages, they are taken to a fake news website, which features the story of a man who managed to make a lot of money working from home. To make the story more believable, the origin of the person featured in the articles changes depending on the victim's IP address.
This is not the first time that an open redirect vulnerability to a CNN subdomain has been exploited by cybercriminals in this way.

