Critical

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

The Hacker News
Actively Exploited

Overview

A cybercrime group known as Gambling Goblin has been targeting Brazilian government and educational websites by installing malicious Apache modules on their servers. This operation, which Check Point Research has been tracking since mid-2025, redirects users from these sites to pages promoting online gambling and sports betting. The attackers are likely Chinese-speaking, and their activities raise concerns about the security of public web infrastructure in Brazil. This incident not only affects the integrity of government and educational institutions but also poses risks to users who may unknowingly interact with these compromised sites. The situation highlights the ongoing challenges in cybersecurity for public entities and the need for robust security measures.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Brazilian government and educational institution web servers running Apache
  • Action Required: Organizations should audit their web server configurations, remove any unauthorized modules, and enhance monitoring of server traffic for unusual activities.
  • Timeline: Ongoing since mid-2025

Original Article Summary

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules

Impact

Brazilian government and educational institution web servers running Apache

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since mid-2025

Remediation

Organizations should audit their web server configurations, remove any unauthorized modules, and enhance monitoring of server traffic for unusual activities.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware, Apache, Check Point.

Related Coverage

Jail time for Maine child in 764 marks turning point in federal law enforcement

CyberScoop

A recent case involving a minor in Maine has resulted in jail time and is being viewed as a significant moment for federal law enforcement regarding violent extremist crime. This case, referred to as '764', marks a first-of-its-kind legal outcome and is expected to influence how similar cases are handled in the future. Researchers tracking the development believe it will create a ripple effect across the landscape of violent extremism, potentially leading to more stringent measures and responses from law enforcement agencies. The implications of this case extend beyond the individual involved, as it could set precedents for dealing with youth and extremism in the United States.

Sep 2, 2026

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

darkreading

Recent reports indicate that SonicWall's SMA 1000 series devices are vulnerable to multiple zero-day exploits, allowing unauthorized remote code execution (RCE). This follows a series of attacks earlier this summer that targeted two other zero-day vulnerabilities in SonicWall's edge devices. The implications of this vulnerability are significant, as it could allow attackers to gain control over affected systems without any authentication. Organizations using these devices need to take immediate action to safeguard their networks, as the vulnerabilities are being actively exploited. Users are advised to monitor for updates from SonicWall and apply patches as soon as they are released to mitigate potential risks.

Sep 2, 2026

OpenLeash Adds a Human Check to Risky AI Agent Actions

SecurityWeek

OpenLeash has introduced a new security feature that acts as a safeguard against risky actions taken by AI agents. This tool monitors the actions of AI systems and can block those that pose clear risks. In situations where the intent of the AI is ambiguous, OpenLeash will prompt a human for approval before proceeding. This approach is particularly important as AI becomes more integrated into various applications, potentially leading to unintended consequences. By adding this layer of human oversight, OpenLeash aims to reduce the likelihood of harmful actions while maintaining the efficiency of AI operations. The development underscores the growing need for responsible AI deployment and oversight in technology.

Sep 2, 2026

The FCC wants consumers to rate their telecom’s anti-robocall protections

CyberScoop

The Federal Communications Commission (FCC) is taking steps to enhance consumer protection against robocalls. They are asking consumers to evaluate their telecom providers’ efforts in blocking these unwanted calls. This initiative aims to empower users while also holding providers accountable for their anti-robocall measures. Additionally, the FCC has removed 14 phone service providers from U.S. networks for failing to comply with existing robocalling regulations. This move underscores the FCC's commitment to reducing the prevalence of robocalls, which can often lead to scams and fraud, affecting millions of Americans.

Sep 2, 2026

Dogged Russia-based botnet dismantled after 23-year run

CyberScoop

The Sality botnet, which has been operating for 23 years, has finally been dismantled by cybersecurity experts and authorities. This Russia-based botnet was notorious for its peer-to-peer infrastructure, which allowed it to evade detection and disruption efforts for an extended period. It has been linked to various cybercrimes, including the distribution of malware and the theft of sensitive information. The takedown of Sality is significant as it represents a major victory in the fight against long-standing cyber threats. Its removal is expected to reduce the incidence of malware infections and enhance overall internet security for users worldwide.

Sep 2, 2026

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

SecurityWeek

The UK government is taking significant steps to enhance its cybersecurity by introducing amendments to the Cyber Security and Resilience Bill. These changes will empower ministers to restrict access to technology providers deemed high-risk for critical infrastructure. This move comes as supply chain attacks are becoming more frequent and sophisticated, posing serious risks to national security and public safety. By limiting the involvement of potentially dangerous tech suppliers, the UK aims to protect essential services and maintain the integrity of its digital infrastructure. This decision affects various sectors, including telecommunications, energy, and transportation, where secure and reliable technology is vital.

Sep 2, 2026