2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

2026-05-28T20:51:37Zc3603a7f3a0611829e84190542d167b13951f1fbba622f3246747424ea29ce83
active-directory-certificate-servicesad-csaptautonomous-ai-attacksbrowser-extensioncaptive-portalcloud-attackscopy-faildetectionextortiongremlin-stealerlinux-kernelmalicious-extensionsmalwarenation-statenpmpan-osransomwareroadtoolsscreening-serpenssupply-chaintamperedcheftgr-sta-1030threat-intel

What happened

Unit 42 published a series of May 2026 reports covering high-risk vulnerabilities, malware trends, nation-state activity and supply-chain/cloud attack techniques. Notable items include exploitation of PAN-OS captive portal (CVE-2026-0300) enabling unauthenticated RCE, the critical Linux kernel local privilege escalation “Copy Fail” (CVE-2026-31431), evolved stealers and RATs (Gremlin stealer, TamperedChef), Screening Serpens APT activity (AppDomainManager hijack and new RAT variants), misuse of ROADtools for cloud intrusions, elevated npm supply-chain risks, AD CS exploitation techniques, high

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
c3603a7f3a0611829e84190542d167b13951f1fbba622f3246747424ea29ce83
Enrichment time
2026-05-28T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.