Unit 42 Palo Alto Networks
- The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIREby Eviatar Garzi on September 10, 2026 at 10:00 am
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.
- Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructureby Rem Dudas on September 9, 2026 at 10:00 am
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin Americaby Reese Lewis and Sara McBroom on September 3, 2026 at 10:00 am
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.
- An AI-Assisted Cyber Attack: Inside a Unit 42 Investigationby Renzon Cruz, Nicolas Bareil, Eric Semaan and Omar Jbari on September 2, 2026 at 10:00 am
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsby Noam Sala on August 31, 2026 at 10:00 am
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
- Perturbation Probing: A New Diagnostic for the Fragility of LLM Safetyby Tony Li, Hongliang Liu and Yuhao Wu on August 28, 2026 at 10:00 pm
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
- The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Executionby Sara McBroom on August 25, 2026 at 10:00 am
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.
- Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chainby Yaron Avital on August 21, 2026 at 11:00 pm
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.
- Identity Abuse Through Trusted Communication Channelsby Bill Batchelor on August 20, 2026 at 10:00 am
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
- Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)by Unit 42 on August 18, 2026 at 7:05 pm
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations’ Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.
- Kimwolf v7: An Evolution of the Kimwolf Botnetby Asher Davila, Chris Navarrete and Doel Santos on August 11, 2026 at 10:00 am
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.
- The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communicationsby Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang on August 10, 2026 at 10:00 pm
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.
- Inside the Modern SOC: The Identity Front Doorby Sharon Maydar on August 7, 2026 at 11:00 pm
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.
- ChainDrop: Inside a Self-Propagating npm Wormby Unit 42 on August 6, 2026 at 10:26 pm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
- Token Jacking: Cybercriminals Could Be Stealing Your AI Resourcesby Unit 42 on August 6, 2026 at 10:00 am
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.






















