Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility
2026-06-10T08:51:39Z•35a1abf55e262b248c69f72c27e2ecf968aa810aabd71506155c0db7fe25e1b6
AD-CSAPTCVE-2026-0257CVE-2026-0300CVE-2026-31431FlutterShellPAN-OScloud-loggingdefense-evasionlinux-kernelmacOSmalvertisingnpmpaloalto_unit42supply-chainvulnerability
What happened
Unit 42 published multiple research reports and threat briefs covering active exploitation and high-impact vulnerabilities, supply chain and cloud threats, and emerging malware campaigns. Notable items include active exploitation of PAN-OS CVE-2026-0257, a PAN-OS captive portal unauthenticated RCE (CVE-2026-0300), the critical Linux kernel local privilege escalation ‘Copy Fail’ (CVE-2026-31431), plus guidance on cloud logging abuse for defense evasion, npm supply chain risks, macOS FlutterShell malvertising, APT Screening Serpens activity, ROADtools misuse in cloud intrusions, AD CS abuse, and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 35a1abf55e262b248c69f72c27e2ecf968aa810aabd71506155c0db7fe25e1b6
- Enrichment time
- 2026-06-10T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.