Find notable cyber news and cases, enriched with sources, timelines, and signals.

CPR Apache and SSH compromise hunt guidance

Advisory/Mitigation
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromised sites. The recommended checks target hidden persistence that can redirect visitors and obscure tampering. The affected scope includes sites abused in the Brazilian SEO fraud campaign.

Related Happenings

Gambling Goblin Brazilian SEO fraud campaign

Campaign
H score33 First: 02.09.2026 17:00 Last: 02.09.2026 17:00 Sources 1

How related: A Chinese-speaking cybercrime cluster has turned compromised Brazilian government and education websites into infrastructure for a sustained SEO fraud campaign operating since mid-2025.

About this happening: The Gambling Goblin operation has been using compromised Brazilian government and education websites as infrastructure for a sustained SEO fraud campaign since mid-2...

Brazilian government websites hit by network compromise

Incident
H score28 First: 16.07.2026 14:58 Last: 16.07.2026 14:58 Sources 1

About this happening: More than 20 Brazilian government websites were hijacked and turned into malware delivery channels, exposing public-sector infrastructure to downstream abuse. The comp...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service

Threat Actor Meta
H score36 First: 19.02.2026 14:00 Last: 19.02.2026 14:00 Sources 1

About this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...

Timeline

  1. 02.09.2026 17:00 2 articles · 0h ago

    Check Point Research advises auditing Apache and SSH after rogue modules hide phishing proxies

    Mitigation Patch Update

    Check Point Research advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes after identifying a sustained SEO fraud campaign that used compromised Brazilian government and education websites as reverse-proxy infrastructure. The malicious Apache modules compiled on victim servers, deleted source files, timestomped the resulting binaries, stripped Content-Security-Policy headers, and redirected selected visitors to phishing pages impersonating Google Play, the Microsoft Store and Amazon.

    Show sources