 | 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface | 2026-05-28 | True | Justin Moore | True | | |
 | Out of the Crypt: The Evolving Cyber Extortion Economy | 2026-05-27 | True | Matt Brady and Justin Moore | True | | |
 | Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns | 2026-05-22 | True | Unit 42 | True | | |
 | Paved With Intent: ROADtools and Nation-State Tactics in the Cloud | 2026-05-22 | True | Bill Batchelor and Eyal Rafian | True | | |
 | Tracking TamperedChef Clusters via Certificate and Code Reuse | 2026-05-20 | True | Joseph Ganter | True | | |
 | Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools | 2026-05-11 | True | Stav Setty, Tom Fakterman and Shachar Roitman | True | | |
 | Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution | 2026-05-07 | True | Justin Moore and Unit 42 | True | | |
 | Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years | 2026-05-05 | True | Justin Moore | True | | |
 | Essential Data Sources for Detection Beyond the Endpoint | 2026-05-01 | True | Corey Berman and Matt Gayford | True | | |
 | That AI Extension Helping You Write Emails? It’s Reading Them First | 2026-04-30 | True | Shresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher, Oleksii Starov, Qinge Xie and Fang Liu | True | | |
 | The npm Threat Landscape: Attack Surface and Mitigations | 2026-04-24 | True | Unit 42 | True | | |
 | TGR-STA-1030: New Activity in Central and South America | 2026-04-24 | True | Unit 42 | True | | |
 | Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System | 2026-04-23 | True | Yahav Festinger and Chen Doytshman | True | | |
 | When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks | 2026-04-22 | True | Emmanuel Zhou, Adam Robbie, Rick Wyble, Zhutian Liu, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy and Mathy Vanhoef | True | | |
 | Fracturing Software Security With Frontier AI Models | 2026-04-20 | True | Andy Piazza | True | | |
 | A Deep Dive Into Attempted Exploitation of CVE-2023-33538 | 2026-04-16 | True | Asher Davila, Malav Vyas and Chris Navarrete | True | | |
 | Cracks in the Bedrock: Agent God Mode | 2026-04-08 | True | Ori Hadad | True | | |
 | Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox | 2026-04-07 | True | Ori Hadad | True | | |
 | Understanding Current Threats to Kubernetes Environments | 2026-04-06 | True | Eyal Rafian and Bill Batchelor | True | | |
 | When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications | 2026-04-03 | True | Jay Chen and Royce Lu | True | | |
 | Threat Brief: Widespread Impact of the Axios Supply Chain Attack | 2026-04-01 | True | Unit 42 | True | | |
 | Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure | 2026-03-31 | True | Unit 42 | True | | |
 | Double Agents: Exposing Security Blind Spots in GCP Vertex AI | 2026-03-31 | True | Ofir Shaty | True | | |
 | Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government | 2026-03-26 | True | Doel Santos and Hiroaki Hara | True | | |
 | Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team | 2026-03-24 | True | Justin Moore | True | | |
 | Google Authenticator: The Hidden Mechanisms of Passwordless Authentication | 2026-03-23 | True | Arie Olshtein | True | | |
 | Who’s Really Shopping? Retail Fraud in the Age of Agentic AI | 2026-03-20 | True | Matt Brady and Christa McHugh | True | | |
 | Analyzing the Current State of AI Use in Malware | 2026-03-19 | True | Unit 42 | True | | |
 | Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models | 2026-03-17 | True | Yu Fu, May Wang, Royce Lu and Shengming Xu | True | | |
 | Boggy Serpens Threat Assessment | 2026-03-16 | True | Unit 42 | True | | |
 | Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization | 2026-03-16 | True | Justin Moore | True | | |
 | Insights: Increased Risk of Wiper Attacks | 2026-03-12 | True | Andy Piazza, Eric Goldstrom and Steve Elovitz | True | | |
 | Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia | 2026-03-12 | True | Lior Rochberger and Yoav Zemah | True | | |
 | Auditing the Gatekeepers: Fuzzing "AI Judges" to Bypass Security Controls | 2026-03-10 | True | Tony Li, Hongliang Liu and Yuhao Wu | True | | |
 | An Investigation Into Years of Undetected Operations Targeting High-Value Sectors | 2026-03-06 | True | Tom Fakterman | True | | |
 | Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild | 2026-03-03 | True | Beliz Kaleli, Shehroze Farooqi, Oleksii Starov and Nabeel Mohamed | True | | |
 | Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran | 2026-03-03 | True | Unit 42 | True | | |
 | Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel | 2026-03-02 | True | Gal Weizman | True | | |
 | VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731) | 2026-02-19 | True | Justin Moore | True | | |
 | Critical Vulnerabilities in Ivanti EPMM Exploited | 2026-02-17 | True | Justin Moore | True | | |
 | Phishing on the Edge of the Web and Mobile Using QR Codes | 2026-02-13 | True | Diva-Oriane Marty, Shehroze Farooqi and Alex Starov | True | | |
 | Nation-State Actors Exploit Notepad++ Supply Chain | 2026-02-11 | True | Unit 42 | True | | |
 | A Peek Into Muddled Libra’s Operational Playbook | 2026-02-10 | True | Justin De Luna, Noah Rincon and Cuong Dinh | True | | |
 | Novel Technique to Detect Cloud Threat Actor Operations | 2026-02-06 | True | Nathaniel Quist | True | | |
 | The Shadow Campaigns: Uncovering Global Espionage | 2026-02-05 | True | Unit 42 | True | | |
 | Privileged File System Vulnerability Present in a SCADA System | 2026-01-30 | True | Asher Davila and Malav Vyas | True | | |
 | Understanding the Russian Cyber Threat to the 2026 Winter Olympics | 2026-01-29 | True | Justin Moore | True | | |
 | The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time | 2026-01-22 | True | Shehroze Farooqi, Alex Starov, Diva-Oriane Marty and Billy Melicher | True | | |
 | DNS OverDoS: Are Private Endpoints Too Private? | 2026-01-20 | True | Unit 42 | True | | |
 | Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering | 2026-01-17 | True | Randy Stone | True | | |