When “Hi, This Is IT” Comes Through Microsoft Teams
2026-06-09T08:51:39Z•dd1d8f02ca10c16cb151d89b8d63262db94e7c8d8580fc122e2a42aea8f1eed5
ad-csaptbrowser-extension-risk','gen-ai-extensions'ci/cdcvecve-2026-0257cve-2026-0300cve-2026-31431fluttergremlin-stealerlinux-kernellpemacosmalvertisingmicrosoft-teamsnpmpan-osphishingrceroadtoolsscreening-serpensstealersupply-chaintamperedchefvulnerability
What happened
Unit 42 RSS roundup highlighting multiple high-impact threats and vulnerability advisories: active exploitation of PAN‑OS (CVE-2026-0257) and a PAN-OS captive portal unauthenticated RCE (CVE-2026-0300); Copy Fail (CVE-2026-31431), a critical Linux kernel LPE affecting millions; macOS malvertising campaign distributing the FlutterShell backdoor; evolving npm supply‑chain and CI/CD attacks; phishing via collaboration platforms (Microsoft Teams); updated intelligence on Screening Serpens APT, TamperedChef clusters, Gremlin stealer evolution, ROADtools misuse in cloud intrusions, AD CS escalation,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- dd1d8f02ca10c16cb151d89b8d63262db94e7c8d8580fc122e2a42aea8f1eed5
- Enrichment time
- 2026-06-09T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.