FBI warns of fake FIFA websites running World Cup fraud schemes
2026-05-28T19:23:33Z•710a1e946ee798c1952d05b931fa9766e7e54aea472b05b87cb91bba351a271c
AI chatbot manipulationCISACVE-2026-35616EKZFortiClient EMSGlasswormGogsLiteSpeedRCESEO poisoningShinyHunters','Silent Ransom GroupWorld Cupactively exploitedauthentication bypassbotnetcPanelcredential theftcryptojackingdata breachextortionfake websitesfraudinfostealerphishingzero-day
What happened
Multiple active threats and fraud schemes were reported: FBI warns of World Cup-themed phishing and fake FIFA websites used to steal personal/financial data and sell fake tickets; attackers are exploiting an authentication-bypass in FortiClient EMS (CVE-2026-35616) to deploy the EKZ credential stealer; an unpatched Gogs zero‑day allows remote code execution on internet-facing instances; CISA issued an emergency 4‑day directive for a critical, actively exploited LiteSpeed cPanel plugin flaw; coordinated SEO‑poisoning and AI‑chatbot manipulation campaigns are distributing GPU‑mining malware; the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 710a1e946ee798c1952d05b931fa9766e7e54aea472b05b87cb91bba351a271c
- Enrichment time
- 2026-05-28T19:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.