These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.
The 2026 Best Practices for Mosque and Community Safety Guide offers practical guidance to help mosques and Islamic community institutions prevent, prepare for, and respond to security threats and hate crimes. It stresses that each facility has unique vulnerabilities shaped by its location, physical layout, surrounding environment, and available resources, making an on-site inspection and professional risk assessment essential for developing appropriate safeguards.
Analyst Comments: Several sections of the guide provide particularly practical resources for institutions looking to strengthen their security posture. The “Three Things to Do Immediately” section offers a clear starting point, including conducting a facility risk assessment and assessing staff and volunteer readiness. The guide also provides an Emergency Contact List and guidance for documenting incidents and preserving evidence, which can support preparedness and response efforts.
The FBI warning highlights a sophisticated form of OAuth consent phishing in which attackers impersonate event coordinators, journalists, officials, or other trusted contacts and send seemingly legitimate invitations, documents, or identity-verification requests. Rather than stealing a password, the malicious link persuades a user to authorize an attacker-controlled application, potentially granting persistent access to email, files, calendars, and other sensitive data even after a password change. Event planners are particularly attractive targets because they routinely communicate with unfamiliar contacts while managing valuable contact, travel, payment, and scheduling information. The warning underscores the need to verify unexpected requests through a separate channel, closely review application permission prompts, restrict unnecessary third-party access, and promptly revoke suspicious authorization tokens.
Analyst Comments: OAuth consent phishing can provide persistent account access without exposing a password. Risk reduction depends on:
The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.