Operation Endgame Disrupts SocGholish Malware Network

Law enforcement agencies in the Netherlands, Canada, Germany, and the United States have conducted a coordinated operation to dismantle the infrastructure of

CyberSecureFox

New #SocGholish C2:

hXXps://gallery.garrettcountygranfondo[.]org/Xgd37BKqtSdK7BK3uIzjYIr5uSbB1ol3tSdD7BKqkw==
gallery.garrettcountygranfondo[.]org
45[.]32.172.21
AS20473 The Constant Company, LLC

🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization

BobDaHacker didn't find a zero-day. She didn't exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to FIFA's public agent registration portal, got added to FIFA's #Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the #FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.

The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an "access denied" page. The backend APIs didn't check anything. FIFA fixed it by the next morning without ever responding to the researcher. She's still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the security.txt file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It's 2026.

→ Week #25/2026 also covers: The #SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the #Anthropic ban dangerous

Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-25-2026-client-side-authorization-is-not-authorization

If you find it useful, subscribe to get it in your inbox every weekend 📨

#infosecMASHUP #cybersecurity #infosec #threatintel #AI

🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization

Plus: The SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the Anthropic ban dangerous

X’s InfoSec Newsletter

Civilians behind international police probe into Russian cybercriminals

https://fed.brid.gy/r/https://globalnews.ca/news/11915435/russian-cybercriminals-scam-wordpress/

Operation Endgame schaltet SocGholish Malware-Infrastruktur ab

Internationale Ermittler haben fast 15.000 infizierte WordPress-Blogs von der Malware „SocGholish“ bereinigt und die zugrunde liegende Botnet-Infrastrukturen vom Netz genommen.

Borns IT- und Windows-Blog
Cyber Journaal S02E73, het Ministerie van Financiën gehackt via een zeroday, de politie rolt het SocGholish netwerk op en bijna 74.000 Fortinet firewalls liggen op straat. https://www.ccinfo.nl/journaal/3235079_financien-gehackt-via-zeroday-politie-rolt-socgholish-op #Cybersecurity #SocGholish #FortiBleed
Financiën gehackt via zeroday, politie rolt SocGholish op

Financiën gehackt via een zerodaylek, de politie rolt het SocGholish netwerk op en bijna 74.000 Fortinet firewalls liggen op straat. Plus kritieke NGINX lekken.

📰 Operation Endgame: Global Law Enforcement Disrupts SocGholish, Cleans 15,000 Infected Websites

✅ SUCCESS: 'Operation Endgame' disrupts the SocGholish botnet linked to Evil Corp! Law enforcement seized 106 servers and cleaned nearly 15,000 infected WordPress sites, crippling a major ransomware entry point. #SocGholish #OpEndgame #Cybercrime

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/global-police-operation-cleans-15000-sites-in-socgholish-takedo…

Fazit: Hätte man Updates zeitnah eingespielt, wäre die Wahrscheinlichkeit geringer gewesen kompromittiert zu werden.

#OperationEndgame: Ermittler säubern tausende Blogs von #SocGholish | Security https://www.heise.de/news/Operation-Endgame-Ermittler-saeubern-tausende-Blogs-von-SocGholish-11337399.html #malware

Operation Endgame: Ermittler säubern tausende Blogs von SocGholish

Strafverfolger aus vier Ländern zerschlugen ein Botnet und Wordpress-Blogs, die Kriminelle als Verteilstationen für Schadsoftware mißbrauchten.

heise online
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group.

BleepingComputer
14,971 WordPress Sites Cleaned in Global SocGholish Takedown

Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning 14,971 WordPress sites used to spread fake-update malware.

Security Affairs