All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
Bluesky
Twitter
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Security researcher gains access to FIFA World Cup 2026 live camera feeds through public agent platform vulnerability

By

BobDaHacker

5h ago· 10 min readenInsight

Summary

A security researcher discovered a critical vulnerability in FIFA's public Agent Platform where anyone could register, gain access to the Football Data Platform's Streaming Management panel, and obtain RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. The researcher spent hours contacting FIFA, MediaKind, HBS, CISA, and the FBI at 3am Tokyo time to report the issue before it was silently fixed without acknowledgment.

Key quotes

· 4 pulled
They fixed it without ever responding to me.
I had to call FIFA, MediaKind, HBS, CISA, and the FBI at 3am Tokyo time just to get someone to listen.
What I didn't expect was what happened next.
When you register on agents.fifa.org, FIFA adds your account to their Microsoft Entra tenant (formerly Azure AD).
Snippet from the RSS feed
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours cal

You might also wanna read