logo

.gov Redirections Leading to Spam: How Did We Get There?

ID: 3bc424c8-a576-5a77-901d-37ce8571db26

STIX ID: report--3bc424c8-a576-5a77-901d-37ce8571db26

Feed Name: Zscaler Security Research Blog

Threat Score
30/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

The report describes how open redirection and related XSS flaws on *.gov websites are being exploited by spammers to bypass URL/spam filters and redirect users to scam pages, outlines why these warning/redirect pages are abused, and recommends mitigations including referrer validation, allowlists, and signing redirect URLs with hashes to ensure only approved redirects are executed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.