FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

2026-06-05T07:24:09Z58a5888ae0f6cb6f228fa38bef552e1dfe6a50a7cead4845b056842c8b847e44
CISA KEVCVE disclosureHTTP/2 BombRATSMTP relayagentic AI securitybackdoorbanking malwarecloud compromisecredential theftdenial-of-serviceespionagegithub-actionmalvertisingmalwaremobile token theftntlm relayphishingremote code executionsupply-chain

What happened

A broad set of active threats and high-impact vulnerabilities were reported across cloud, enterprise, and consumer ecosystems. Highlights include large-scale FIFA-themed phishing and banking-malware campaigns, cloud server hijacks (PCPJack) to build an SMTP relay, malvertising distributing a new macOS backdoor (FlutterShell), and fake open-source sites using a TDS to deliver stealers and RATs. Multiple serious vulnerabilities and exploits were disclosed or observed in the wild — notably CVE-2026-45247 (Magento RCE added to CISA KEV), CVE-2026-23479 (Redis authenticated RCE), CVE-2026-20230 (ex

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
58a5888ae0f6cb6f228fa38bef552e1dfe6a50a7cead4845b056842c8b847e44
Enrichment time
2026-06-05T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.