Security Alert for Legal AF Readers: Malvertising Detected on Today’s Post
April 14 post “State Revolt Delivers Devastating Blow to Trump Scheme:" Bitdefender Total Security detected & blocked two live threats
I’m John Liccione, Democratic candidate for Congress in Florida’s 13th District and a U.S. Air Force / NSA veteran with decades of cyber and tech experience, I want to alert Michael Popok and the entire Legal AF community to a security issue I just encountered.
While watching the April 14 post “State Revolt Delivers Devastating Blow to Trump Scheme,” my Bitdefender Total Security blocked two live threats:
April 4 – Malicious redirector (Generic.JS.Redirector.A.00D8EC0B) trying to load https://teachmeiwnd.com/services/?id=156685
April 14 at 4:03 PM – Suspicious connection attempt to www.tsl-logistics.ru using a mismatched certificate
My Bitdefender stopped both cold. No infection occurred.
This is textbook malvertising — malicious ads or scripts injected into legitimate sites. It’s happening more frequently across news and newsletter platforms.
My recommendation to Legal AF and all Substack creators and readers
Immediately audit ad networks and embedded content (especially video players)
Tighten third-party script permissions
Work with Substack on stronger platform-wide protections
Readers: keep your antivirus updated, use an ad-blocke, and never click “Add to exceptions” on these alerts.
Legal AF is essential accountability journalism. Let’s make sure bad actors can’t weaponize the platform against the very people fighting for democracy.
Screenshots and logs available if the team wants them.
John Liccione
Rebel Progressive Democratic Candidate for U.S. Congress, Florida District 13
johnforpinellas.com




I want to say that I have been having major issues. I found an security issue that had been added on to my account. I have been experiencing major issues especially with Substack. Not all folks run ads on their sites but the ones that do make me nervous. I had to look up what all of these extensions were and found one that was identified as likely malware.