2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
2026-05-28T20:51:37Z•c3603a7f3a0611829e84190542d167b13951f1fbba622f3246747424ea29ce83
active-directory-certificate-servicesad-csaptautonomous-ai-attacksbrowser-extensioncaptive-portalcloud-attackscopy-faildetectionextortiongremlin-stealerlinux-kernelmalicious-extensionsmalwarenation-statenpmpan-osransomwareroadtoolsscreening-serpenssupply-chaintamperedcheftgr-sta-1030threat-intel
What happened
Unit 42 published a series of May 2026 reports covering high-risk vulnerabilities, malware trends, nation-state activity and supply-chain/cloud attack techniques. Notable items include exploitation of PAN-OS captive portal (CVE-2026-0300) enabling unauthenticated RCE, the critical Linux kernel local privilege escalation “Copy Fail” (CVE-2026-31431), evolved stealers and RATs (Gremlin stealer, TamperedChef), Screening Serpens APT activity (AppDomainManager hijack and new RAT variants), misuse of ROADtools for cloud intrusions, elevated npm supply-chain risks, AD CS exploitation techniques, high
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- c3603a7f3a0611829e84190542d167b13951f1fbba622f3246747424ea29ce83
- Enrichment time
- 2026-05-28T20:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.