Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility

2026-06-10T08:51:39Z35a1abf55e262b248c69f72c27e2ecf968aa810aabd71506155c0db7fe25e1b6
AD-CSAPTCVE-2026-0257CVE-2026-0300CVE-2026-31431FlutterShellPAN-OScloud-loggingdefense-evasionlinux-kernelmacOSmalvertisingnpmpaloalto_unit42supply-chainvulnerability

What happened

Unit 42 published multiple research reports and threat briefs covering active exploitation and high-impact vulnerabilities, supply chain and cloud threats, and emerging malware campaigns. Notable items include active exploitation of PAN-OS CVE-2026-0257, a PAN-OS captive portal unauthenticated RCE (CVE-2026-0300), the critical Linux kernel local privilege escalation ‘Copy Fail’ (CVE-2026-31431), plus guidance on cloud logging abuse for defense evasion, npm supply chain risks, macOS FlutterShell malvertising, APT Screening Serpens activity, ROADtools misuse in cloud intrusions, AD CS abuse, and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
35a1abf55e262b248c69f72c27e2ecf968aa810aabd71506155c0db7fe25e1b6
Enrichment time
2026-06-10T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility · Baitaphish