---
title: "Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10, 2024] | DuoCircle"
description: "Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/"
---

Quick Answer

Five stories. Trustwave detailed phishing emails using HTML attachments that abuse the search-ms protocol to open Windows Search and run remote scripts hosted on attacker-controlled WebDAV shares. CISA warned of an ongoing impersonation scam where callers pose as agency staff and ask victims to wire money or buy gift cards. The City of Cleveland shut down most non-emergency systems after a cyberattack disrupted City Hall operations. Elastic Security Labs documented Warmcookie, a Windows backdoor distributed through fake recruiter emails offering job opportunities. And the Synnovis ransomware attack continued to cause blood shortages and surgery cancellations across major London hospitals, with NHS appealing for O-type donors.

Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News \[June 10, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/06/Phishing-Exploits-Windows-CISA-Scam-Alert-Cleveland-Cyber-Response-–-Cybersecurity-News-June-10-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Phishing%20Exploits%20Windows%2C%20CISA%20Scam%20Alert%2C%20Cleveland%20Cyber%20Response%2C%20Cybersecurity%20News%20%5BJune%2010%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F&title=Phishing%20Exploits%20Windows%2C%20CISA%20Scam%20Alert%2C%20Cleveland%20Cyber%20Response%2C%20Cybersecurity%20News%20%5BJune%2010%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Phishing%20Exploits%20Windows%2C%20CISA%20Scam%20Alert%2C%20Cleveland%20Cyber%20Response%2C%20Cybersecurity%20News%20%5BJune%2010%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F "Share via Email") 

![Cybersecurity News](https://media.mailhop.org/duocircle/images/2024/06/DMARC-report-check.jpg) 

We’re back with cybersecurity’s latest in our latest news piece. This week, there were several [cybersecurity](/) threats, including phishing emails that exploit a weakness in **Windows Search** to deliver [malware](/resources/upatre-malware-spams), impersonation scams by people pretending to be from CISA, a [cyberattack](https://edition.cnn.com/2024/05/29/tech/ransomware-attacks-hospitals-patients-danger/index.html) that shut down many government services in Cleveland, a new kind of Windows malware called Warmcookie that spreads through **fake job postings**, and a blood shortage in London hospitals caused by a ransomware attack. Here’s everything about these!

## Phishing Emails Exploit Windows Search Protocol to Deliver Malicious Scripts

There is a new [phishing campaign](https://www.bbc.com/news/articles/cp3371r7l1vo) that is using **HTML attachments** to abuse Windows search protocol to deliver malware.

_The Window search protocol is a URI (Uniform Resource Identifier) that allows applications to open Windows Explorer via searches_. Most of these searches are usually at the **local drive index**, but [threat actors](https://www.techtarget.com/searchsecurity/news/366587176/Threat-actor-targeting-Snowflake-database-customers) can force it to query file shares on remote hosts as well. Threat actors are using it to share malicious files and carry out potent attacks.

Researchers at Trustwave have [reported that](https://web.archive.org/web/20251018165150/https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/search-spoof-abuse-of-windows-search-to-redirect-to-malware/) there is an ongoing campaign where the threat actors send malicious emails with HTML attachments. They are invoice documents placed **within a ZIP file** that helps them evade security and AC scanners. When the HTML document is opened, it automatically opens a malicious URL via [meta tag refreshes](https://en.wikipedia.org/wiki/Meta%5Frefresh).

If the refreshes fail, there’s also an **anchor tag** **with a clickable**. The URL is for the Windows search protocol and performs a search on a remote host from where it retrieves a shortcut LNK file. If you click on the file, it will take you to a [batch script](https://www.seobility.net/en/wiki/Batch%5FScripting) on the same server which is malicious.

The researchers could not find out exactly what this batch file does but it cannot be anything good. It’s **best to stay away** from unsolicited emails and take proper [phishing protection](/email/phishing-protection) measures.

## CISA Alerts on Scammers Posing as Its Employees in Phone Calls

This week, CISA (Cybersecurity and Infrastructure Security Agency) issued an alert that threat actors are [impersonating its employees](https://kstp.com/kstp-news/local-news/hennepin-county-sheriffs-office-warns-against-scam-callers-impersonating-its-employees/) on phone calls and deceiving victims to **steal their funds**.

[![Vishing Statistics](https://media.mailhop.org/duocircle/images/2024/06/Office-365-migration.jpg)](https://media.mailhop.org/duocircle/images/2024/06/Office-365-migration.jpg)

_Threat actors have started a **new trend of legitimizing** their scams by using names and details of government employees_. It seems that even CISA is not safe, as they warned in their report. CISA0 [shared](https://www.cisa.gov/news-events/alerts/2024/06/12/phone-scammers-impersonating-cisa-employees) how they’re aware of recent impersonation scammers that are posing as individuals from the agency and also clarified that official staff will never contact anyone with a suspicious [request to wire money](https://kdvr.com/news/local/man-loses-nearly-100k-in-home-down-payment-wire-transfer-scam/), cash, crypto, or even use gift cards.

They also shared tips that if you do get one of these calls, you should **never give in to the demands** and note down the scammer’s number. You can check the contact by calling CISA at **844-729-2472 (844-SAY-CISA)** and report the scam attempt to law enforcement.

The FTC (Federal Trade Commission) also issued a warning back in March about scammers [impersonating FTC employees](https://fortune.com/2024/03/20/scammers-scams-federal-trade-commission-ftc-amazon/) to defraud citizens of their hard-earned money. Many people fell victim to these scams, where the scammers posed as FTC staff and used [social engineering](/phishing-protection/social-engineering-is-a-growing-threat/) tricks to dupe them out of their finances.

The losses of [impersonation scams](https://www.mycentraloregon.com/2024/06/17/irs-warns-of-impersonation-scams/) **crossed $1.1 billion in 2023**, which is a 300% increase from 2020.

## Cleveland Halts Systems in Response to Cyberattack

The City of Cleveland was the victim of a cyberattack this week and is **still recovering**.

The cyberattack has forced the City to take down major citizen-facing services like **public offices** and facilities. Cleveland is a significant center for healthcare, manufacturing, finance, logistics, education, and technological sectors, so the attack is causing major problems. The City’s authorities [issued](https://x.com/CityofCleveland/status/1800150240890441922) a warning to the public that all public services were reduced to only the essential operations as a result of a [cyber incident](https://www.ksn.com/news/local/city-of-wichita-provides-another-update-on-cyber-security-incident-expect-billing-statements/) that it is facing.

The incident is still being investigated by the officials with the help of third-party experts. The City shared that no information from the public utility service [database was accessed](https://www.bleepingcomputer.com/news/security/dell-warns-of-data-breach-49-million-customers-allegedly-affected/) by the threat actors, and the incident **did not impact emergency services** like police, ambulance, fire, and travel.

The authorities **will keep sharing updates** as soon as more information comes to light but no [ransomware gang](https://www.bleepingcomputer.com/news/security/keytronic-confirms-data-breach-after-ransomware-gang-leaks-stolen-files/) has claimed responsibility for the attack yet. You can call the officials at 311 for more information regarding this.

## Warmcookie Windows Backdoor Spread Through Fake Job Opportunities

There’s also a new [Windows malware](https://www.bleepingcomputer.com/news/security/black-basta-ransomware-gang-linked-to-windows-zero-day-attacks/) that has been **circling corporate networks** via fake job offer phishing campaigns.

The name of the malware is **Warmcookie**, and it was [discovered](https://www.elastic.co/security-labs/dipping-into-danger) by Elastic Security labs while they were analyzing the new campaign. _The malware is capable of capturing screenshots and deploying additional payloads._

The attacks start with a phishing campaign that uses fake job and recruitment offers that are sent via [phishing emails](https://www.scmagazine.com/news/github-phishing-campaign-wipes-repos-extorts-victims). Some of these are also [spear phishing](/content/spear-phishing-protection/spear-phishing-examples) emails and are **personalized with the names** and current employer information of the victims.

The emails have a link that is advertised as being a link to the internal recruitment platform for the job agency but actually, it takes you to a [phishing page](https://thehackernews.com/2024/06/moreeggs-malware-disguised-as-resumes.html) **mimicking the official portal**. These portals include a CAPTCHA that you have to fill out, and if you do, it will download a [JavaScript file that downloads the malware](https://www.techworm.net/2024/04/developers-with-fake-job-offer-malware.html) and copies it to the system. It establishes contact with the threat actor’s C2 (Command and Control) server and starts fingerprinting the victim’s system. _It can also **do a ton of harm** as it can steal, retrieve victim information, capture screenshots, enumerate programs, execute commands, and exfiltrate other data._

Warmcookie has been out in the wild for quite some time and was also discovered by eSentire in 2023.

[![Phishing](https://media.mailhop.org/duocircle/images/2024/06/SMTP-providers-1484.jpg)](https://media.mailhop.org/duocircle/images/2024/06/SMTP-providers-1484.jpg)

## London Hospitals Experience Blood Shortage Due to Synnovis Ransomware Attack

_The NHSBT (NHS Blood and Transplant) in England also issued an **urgent call** for O Positive and O Negative blood donors to book appointments after the [Ransomware attack](https://securityboulevard.com/2024/06/a-deep-dive-into-the-economics-and-tactics-of-modern-ransomware-threat-actors/)._

Last week, there was a cyberattack by the [Russian threat actor group](https://www.infosecurity-magazine.com/news/russian-apt28-gooseegg-hacking/) Qilin on the pathology provider Synnovis that **impacted many hospitals** in London. At the time, it halted blood transfusions and also resulted in cancellations or reschedules for the patient.

Now, the NHS has [announced](https://www.nhsbt.nhs.uk/news/o-positive-and-o-negative-donors-asked-to-urgently-book-appointments-to-give-blood-following-london-hospitals-it-incident/) that the hospitals that were affected are unable to match blood donor and recipient types in the rush, so there’s a risk of transfusion matches, which could threaten the lives of the patients. For the patients who could not wait, the doctors opted to use O Negative and O Positive blood reserves for safe transfusion, which has **resulted in a decrease** in the reserves for these.

[Synnovis](https://www.selondonics.org/synnovis-cyber-attack/) has not given any updates regarding the cyber attack since 4 June but NHS is asking individuals that have either of these blood types to donate their blood. Do **call and book an appointment** as your contribution will save a life.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Phishing%20Exploits%20Windows%2C%20CISA%20Scam%20Alert%2C%20Cleveland%20Cyber%20Response%2C%20Cybersecurity%20News%20%5BJune%2010%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2024%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10, 2024]","description":"Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/","datePublished":"2024-06-18T13:14:14.000Z","dateModified":"2025-08-25T11:58:46.000Z","dateCreated":"2024-06-18T13:14:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1149,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/06/DMARC-report-check.jpg","caption":"Cybersecurity News","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10, 2024]","description":"Phishing Exploits Windows, CISA Scam Alert, Cleveland Cyber Response, Cybersecurity News [June 10.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/","datePublished":"2024-06-18T13:14:14.000Z","dateModified":"2025-08-25T11:58:46.000Z","dateCreated":"2024-06-18T13:14:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1149,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/06/DMARC-report-check.jpg","caption":"Cybersecurity News","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
