🔔 Heads-up: There is currently a #phishing campaign targeting #Codeberg users.
If you receive a notification that insults you and your project for poor code quality, combined with an offer to "fix" the problems when you send some money, please ignore and report to us: Mention "@moderation" in response to the issue or forward the email to abuse@codeberg.org.
We are trying to stay ahead of the noise before the notifications are sent.
If you receive in-app notifications which lead to 404 pages or threads that don't contain new messages, it is also likely that they have been cleaned up.
Unfortunately, it is currently very difficult to also remove the notifications when deleting spam users.
We apologize for the inconvenience.
Hint: If "security researchers" or "computer experts" link to an http-only website, you can almost always consider it a scam.
@Codeberg Kinda wonder how some of these posts look like...
@andre_601 There are screenshots circulating, like here: https://mastodon.ar.al/@aral/113685354497245219
@Codeberg I saw one of those and was looking for a "report spam" button ;)
@jwildeboer Unfortunately, there is none at the moment, because abuse tracking inside Forgejo itself is still WIP.
@Codeberg I went to the mentioned website in the spam and apparently a similar attack happened a few weeks ago on GitHub impersonating the same guy who had nothing to do with the spam. 🤨 https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/
@be You're right. We were already aware of this, but I can see how the messaging was not clear. ("security researcher" being perceived as sarcasm towards the person being smeared, when it was actually referring to the spammer)
I edited the post so as to fix this.
@Codeberg We have received one of these issues but it was deleted, likely by your moderation team.
We believe that this _has_ to be a bot or something. As @be said, it seemed that they were subject to another impersonation attempt on GitHub. Also, the latest @gperson (hi again) was on your CI feedback repo which...doesn't contain any code.
@tenacity @be @gperson Yup, the spammer is indeed impersonating a security researcher so as to smear them. We corrected the following post for clarity: https://social.anoxinon.de/@Codeberg/113686200690104994
~n