logo

Palo Alto Networks Unit 42

ID: c8d50a5a-c805-599d-99ad-5b5f5e92b089

STIX ID: identity--c8d50a5a-c805-599d-99ad-5b5f5e92b089

Feed Type: rss

Earliest post: 2024-03-15

Latest post: 2026-08-25

Deep-dive threat research, malware analysis, and intelligence from Palo Alto Networks’ elite Unit 42 team.

01/01/2020
08/28/2026
Title Date Published Describes IncidentAuthorVisible
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution2026-08-25TrueSara McBroomTrue
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain2026-08-21TrueYaron AvitalTrue
Identity Abuse Through Trusted Communication Channels2026-08-20TrueBill BatchelorTrue
Kimwolf v7: An Evolution of the Kimwolf Botnet2026-08-11TrueAsher Davila, Chris Navarrete and Doel SantosTrue
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications2026-08-10TrueChris Navarrete, Sai Sathvik Ruppa and Haozhe ZhangTrue
Inside the Modern SOC: The Identity Front Door2026-08-07TrueSharon MaydarTrue
ChainDrop: Inside a Self-Propagating npm Worm2026-08-06TrueUnit 42True
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources2026-08-06TrueUnit 42True
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software2026-08-04TrueXu ZouTrue
Almost Half of Malware Samples Communicate Direct to IP2026-08-04TrueShu Wang, Zhanhao Chen and Daiping LiuTrue
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication2026-08-03TrueArie OlshteinTrue
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version2026-07-31TrueAdva Gabay and Noa DekelTrue
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks2026-07-30TrueAndy PiazzaTrue
Russian Global Webmail Espionage2026-07-23TrueUnit 42True
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy2026-07-17TrueEmmanuel Zhou, Adam Robbie, Rick Wyble and Miguel PereiraTrue
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report2026-07-16TrueRia BhatiaTrue
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development2026-07-15TrueChris Navarrete, Asher Davila and Doel SantosTrue
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware2026-07-10TrueMatt BradyTrue
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation2026-07-07TrueBharath Nannaka and Pranay Kumar ChhaparwalTrue
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector2026-07-01TrueKeerthiraj Nagaraj, Diva-Oriane Marty, Beliz Kaleli and Oleksii StarovTrue
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure2026-06-25TrueUnit 42True
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat2026-06-23TrueShresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher and Oleksii StarovTrue
The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration2026-06-22TrueYahav FestingerTrue
Threat Brief: Mitigating Large-Scale Credential Attacks2026-06-20TrueAndy PiazzaTrue
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE2026-06-16TrueOri HadadTrue
Inside the Modern SOC: The 72-Minute Race2026-06-15TrueSharon MaydarTrue
Trust No Skill: Integrity Verification for AI Agent Supply Chains2026-06-11TrueYuhao Wu, Tony Li and Hongliang LiuTrue
Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility2026-06-09TrueYahav FestingerTrue
When “Hi, This Is IT” Comes Through Microsoft Teams2026-06-08TrueBill BatchelorTrue
Threat Brief: Active Exploitation of PAN-OS CVE-2026-02572026-06-05TrueAndy Piazza and Unit 42True
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor2026-06-02TrueIdo Asher, Noa Dekel and Tom FaktermanTrue
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface2026-05-28TrueJustin MooreTrue
Out of the Crypt: The Evolving Cyber Extortion Economy2026-05-27TrueMatt Brady and Justin MooreTrue
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns2026-05-22TrueUnit 42True
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud2026-05-22TrueBill Batchelor and Eyal RafianTrue
Tracking TamperedChef Clusters via Certificate and Code Reuse2026-05-20TrueJoseph GanterTrue
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files2026-05-15TruePranay Kumar Chhaparwal and Mark LimTrue
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools2026-05-11TrueStav Setty, Tom Fakterman and Shachar RoitmanTrue
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution2026-05-07TrueJustin Moore and Unit 42True
Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years2026-05-05TrueJustin MooreTrue
Essential Data Sources for Detection Beyond the Endpoint2026-05-01TrueCorey Berman and Matt GayfordTrue
That AI Extension Helping You Write Emails? It’s Reading Them First2026-04-30TrueShresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher, Oleksii Starov, Qinge Xie and Fang LiuTrue
The npm Threat Landscape: Attack Surface and Mitigations2026-04-24TrueUnit 42True
TGR-STA-1030: New Activity in Central and South America2026-04-24TrueUnit 42True
Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System2026-04-23TrueYahav Festinger and Chen DoytshmanTrue
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks2026-04-22TrueEmmanuel Zhou, Adam Robbie, Rick Wyble, Zhutian Liu, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy and Mathy VanhoefTrue
Fracturing Software Security With Frontier AI Models2026-04-20TrueAndy PiazzaTrue
A Deep Dive Into Attempted Exploitation of CVE-2023-335382026-04-16TrueAsher Davila, Malav Vyas and Chris NavarreteTrue
Cracks in the Bedrock: Agent God Mode2026-04-08TrueOri HadadTrue
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox2026-04-07TrueOri HadadTrue

1–50 of 233