home.social

#socgholish — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #socgholish, aggregated by home.social.

fetched live
  1. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  2. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  3. 📢 ENDGAME REMEDIATION - SOCGHOLISH | Following last week’s announcement and today’s update from Europol (link below), the disruption effort against SocGholish has expanded to include Amadey and StealC.

    Spamhaus is now sending notification emails 📩 to hosters of confirmed compromised WordPress sites.

    Here's what to do if you receive one:

    👉 Go to this remediation webpage: spamhaus.org/endgame-socgholish
    👉 Enter the access code included in the email
    👉 Download the list of compromised WordPress administrator credentials
    👉 Verify and where necessary, contact the owner to update their credentials, enable multi-factor authentication, remove any unrecognised WordPress accounts, and ensure your WordPress installation is fully up to date. (there's a ready-made email template for you to use on the remediation webpage 😀)

    Thank you to everyone who is part of this effort.

    Europol announcement: europol.europa.eu/media-press/

    #Trustandsafety #Endgame #SocGholish #Disruption #Infosec #CyberSecurity #Malware

  4. 📢 ENDGAME REMEDIATION - SOCGHOLISH | Following last week’s announcement and today’s update from Europol (link below), the disruption effort against SocGholish has expanded to include Amadey and StealC.

    Spamhaus is now sending notification emails 📩 to hosters of confirmed compromised WordPress sites.

    Here's what to do if you receive one:

    👉 Go to this remediation webpage: spamhaus.org/endgame-socgholish
    👉 Enter the access code included in the email
    👉 Download the list of compromised WordPress administrator credentials
    👉 Verify and where necessary, contact the owner to update their credentials, enable multi-factor authentication, remove any unrecognised WordPress accounts, and ensure your WordPress installation is fully up to date. (there's a ready-made email template for you to use on the remediation webpage 😀)

    Thank you to everyone who is part of this effort.

    Europol announcement: europol.europa.eu/media-press/

    #Trustandsafety #Endgame #SocGholish #Disruption #Infosec #CyberSecurity #Malware

  5. 🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization

    BobDaHacker didn't find a zero-day. She didn't exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to FIFA's public agent registration portal, got added to FIFA's #Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the #FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.

    The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an "access denied" page. The backend APIs didn't check anything. FIFA fixed it by the next morning without ever responding to the researcher. She's still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the security.txt file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It's 2026.

    → Week #25/2026 also covers: The #SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the #Anthropic ban dangerous

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨

    #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  6. 🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization

    BobDaHacker didn't find a zero-day. She didn't exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to FIFA's public agent registration portal, got added to FIFA's #Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the #FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.

    The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an "access denied" page. The backend APIs didn't check anything. FIFA fixed it by the next morning without ever responding to the researcher. She's still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the security.txt file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It's 2026.

    → Week #25/2026 also covers: The #SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the #Anthropic ban dangerous

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨

    #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  7. Cyber Journaal S02E73, het Ministerie van Financiën gehackt via een zeroday, de politie rolt het SocGholish netwerk op en bijna 74.000 Fortinet firewalls liggen op straat. ccinfo.nl/journaal/3235079_fin #Cybersecurity #SocGholish #FortiBleed

  8. Fazit: Hätte man Updates zeitnah eingespielt, wäre die Wahrscheinlichkeit geringer gewesen kompromittiert zu werden.

    #OperationEndgame: Ermittler säubern tausende Blogs von #SocGholish | Security heise.de/news/Operation-Endgam #malware

  9. Fazit: Hätte man Updates zeitnah eingespielt, wäre die Wahrscheinlichkeit geringer gewesen kompromittiert zu werden.

    #OperationEndgame: Ermittler säubern tausende Blogs von #SocGholish | Security heise.de/news/Operation-Endgam #malware

  10. Operation Endgame abbatte SocGholish: 100 server offline e 15.000 siti risanati nell’operazione contro Evil Corp

    Il 18 giugno 2026 un'operazione internazionale di law enforcement ha colpito TA569, il gruppo legato a Evil Corp che distribuisce SocGholish attraverso siti web compromessi. Oltre 100 server abbattuti, quasi 15.000 siti risanati. Ecco la ricostruzione tecnica completa.

    insicurezzadigitale.com/operat

  11. Operation Endgame abbatte SocGholish: 100 server offline e 15.000 siti risanati nell’operazione contro Evil Corp

    Il 18 giugno 2026 un'operazione internazionale di law enforcement ha colpito TA569, il gruppo legato a Evil Corp che distribuisce SocGholish attraverso siti web compromessi. Oltre 100 server abbattuti, quasi 15.000 siti risanati. Ecco la ricostruzione tecnica completa.

    insicurezzadigitale.com/operat

  12. 📣🚨 disrupts TA569’s SocGholish malware infrastructure, with law enforcement taking down 100+ C2 servers and cleaning 15,000 hacked sites.

    Read: hackread.com/operation-endgame

  13. 🔥 Operation Endgame is back! This latest operation targets #SocGholish (FakeUpdates) malware, used by the notorious criminal group: Evil Corp. It's another major international effort that’s taken down 106 servers and domains, with 14,971 infected WordPress websites remediated.

    Excellent work by all partners involved!! 👏 👏

    🔧 REMEDIATION: As with previous phases of #OperationEndgame, Spamhaus is proud to support remediation efforts. Website owners affected by this operation will be contacted with guidance on the next steps.

    ➡️ Dutch National Police press release: politie.nl/en/news/2026/juni/1
    ➡️ Operation Endgame: operation-endgame.com

    #CyberSecurity #ThreatIntelligence #SocGholish #FakeUpdates #Malware #EvilCorp #OperationEndgame

  14. 🔥 Operation Endgame is back! This latest operation targets #SocGholish (FakeUpdates) malware, used by the notorious criminal group: Evil Corp. It's another major international effort that’s taken down 106 servers and domains, with 14,971 infected WordPress websites remediated.

    Excellent work by all partners involved!! 👏 👏

    🔧 REMEDIATION: As with previous phases of #OperationEndgame, Spamhaus is proud to support remediation efforts. Website owners affected by this operation will be contacted with guidance on the next steps.

    ➡️ Dutch National Police press release: politie.nl/en/news/2026/juni/1
    ➡️ Operation Endgame: operation-endgame.com

    #CyberSecurity #ThreatIntelligence #SocGholish #FakeUpdates #Malware #EvilCorp #OperationEndgame

  15. New season of #OperationEndgame just dropped.
    This time, they targeted #SocGholish.
    106 servers and domains taken down, 14.971 websites remediated.
    Of course, they released a movie like video for it again.
    Press release: politie.nl/en/news/2026/juni/1
    #OpEndgame #SocGholish

  16. New season of #OperationEndgame just dropped.
    This time, they targeted #SocGholish.
    106 servers and domains taken down, 14.971 websites remediated.
    Of course, they released a movie like video for it again.
    Press release: politie.nl/en/news/2026/juni/1
    #OpEndgame #SocGholish

  17. Watch out as new research shows SocGholish Malware as Service (MaaS) is exploiting compromised websites and fake software updates to push ransomware and infostealers worldwide.

    Read: hackread.com/socgholish-malwar

  18. Watch out as new research shows SocGholish Malware as Service (MaaS) is exploiting compromised websites and fake software updates to push ransomware and infostealers worldwide.

    Read: hackread.com/socgholish-malwar

    #SocGholish #Malware #FakeUpdates #Ransomware #InfoStealer

  19. @filippo the copy/paste technique is called #ClickFix . the site in the image is infected by TA2726's Keitaro which is well known for sending Windows folks to #SocGholish . what they do with macOS folks has changed over the years. i see they sent you to something that delivered what looks like Poseidon Stealer.

    medium.com/@MateoPappa/letsdef

  20. @filippo the copy/paste technique is called #ClickFix . the site in the image is infected by TA2726's Keitaro which is well known for sending Windows folks to #SocGholish . what they do with macOS folks has changed over the years. i see they sent you to something that delivered what looks like Poseidon Stealer.

    medium.com/@MateoPappa/letsdef

  21. DomainTools Investigations’ (DTI) latest analysis uncovers a technically sophisticated malware campaign that uses fake CAPTCHAs and spoofed document verification pages (like Docusign) to trick users into self-infecting their machines with the NetSupport RAT.

    Key tactics include:

    🔹 Clipboard poisoning via fake CAPTCHA pages
    🔹Multi-stage PowerShell downloaders
    🔹Spoofed Gitcodes and Docusign domains
    🔹Infrastructure overlap with known threat groups like SocGholish, FIN7 and STORM-0408

    Read the full breakdown including security recommendations here: dti.domaintools.com/how-threat

    #ThreatIntelligence #CyberSecurity #SocGholish #Malware

  22. We’re seeing an increasing volume of blocked queries to the SocGholish-related domain - blackshelter[.]org in the last several days.

    #DNS #SocGholish #ransomware #malware #infosec