A Chinese-speaking threat actor dubbed “Gambling Goblin” is compromising trusted Brazilian government web servers (including .gov.br sites) and turning them into infrastructure for phishing at scale. The intrusions quietly install malicious modules that act as reverse proxies for gambling and sports betting content, impersonating brands and app stores with fabricated reviews and ratings. The effort underscores how attackers can monetize trust in legitimate domains—often with low user visibility and high operational scale.
Key takeaway: treat defacement-turned-proxy behavior as a high-priority incident pattern, and audit third-party web components and server-side proxying/redirect behaviors on externally facing government- or brand-hosted assets.
Source: Check Point Blog
Zero-Day Spotlight: SonicWall SMA 1000 Under Active Attack via Chained Exploits
SonicWall has confirmed two previously undisclosed vulnerabilities in SMA 1000 appliances (CVE-2026-83548 and CVE-2026-83549) are being exploited in the wild. The flaws can be chained to progress from pre-auth SSRF to higher-impact outcomes, including unauthenticated remote code execution in practical attack flows. Because exploitation was occurring before disclosure, patching alone is not sufficient—organizations must also assess whether compromise already occurred.
Key takeaway: prioritize appliance hotfixes/upgrades immediately and begin compromise checks (including indicators of compromise, credential resets, and investigation/possible re-imaging for exposed gateways).
Source: Help Net Security
~22,000 Unpatched Microsoft Exchange Servers Exposed to Critical Auth Bypass
Shadowserver scans indicate nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass flaw described by Microsoft as capture-replay. The exposure is heavily concentrated in the US and Germany, creating a broad attack surface for authorized attackers attempting to escalate privileges. The fix was released on August 11, 2026, but many systems appear to remain vulnerable.
Key takeaway: verify patch status and exposure (especially internet-facing Exchange) immediately, and validate whether any suspicious authentication/replay patterns have already occurred.
Source: Help Net Security
FBI Warns of OAuth Consent Phishing Targeting Prominent Individuals
The FBI’s IC3 warns that attackers are targeting prominent individuals and their relatives/contacts using “OAuth consent phishing” (a passwordless approach that leverages deceptive authorization flows). The activity has reportedly been ongoing since late 2025 and focuses on gaining persistent access to accounts—including private emails and files—without requiring attackers to crack credentials. This makes “account security” inseparable from “app authorization hygiene.”
Key takeaway: enforce strong verification for OAuth app grants, monitor for unusual consent events, and educate targeted users to treat unexpected consent prompts as potentially malicious.
Source: Help Net Security
Dark Web Claims: 153M Driver’s License Scans for Sale as FBI Probes idscan.net
A dark web marketplace listing reportedly offers 153 million driver’s license records (driver’s license scans) with additional IDs “up for sale,” prompting investigation activity tied to idscan.net. If accurate, the data would be highly reusable for identity theft, account recovery fraud, and synthetic identity programs. The case highlights how verification databases can become extremely high-value targets even when the original breach mechanism isn’t publicly confirmed yet.
Key takeaway: assume identity data can accelerate fraud chains—review account takeover controls, step-up authentication, and recovery process hardening for affected geographies and user segments.
Source: Malwarebytes Blog
AI Agent Safety Gap: “System Prompts Aren’t Security Controls”
New guidance emphasizes that AI agents require security enforcement at the access-control layer—not in the agent’s system prompt. The core risk: prompts can be overridden or misinterpreted, while authorization must be applied during retrieval/execution based on user permissions. The recommendation aligns with a broader theme in “agentic security”: telemetry and guardrails must be coupled to real policy decision points.
Key takeaway: implement retrieval-time scoping (RBAC/ABAC), auditable decision traces, and pre-execution action constraints—especially for agents that use tools, credentials, or shared infrastructure.
Source: Help Net Security
You May Also Be Interested In...
23-Year-Old Sality Botnet Disruption Signals Long-Run P2P Malware Can Still Be Unwound
Malicious .git Configs Can Turn AI Coding Agents Into Malware Launchers
Stolen Claude Session Cookies: Session Theft Can Bypass Revocation Limits