Unit 42 Palo Alto Networks
- Russian Global Webmail Espionageby Unit 42 on July 23, 2026 at 2:10 pm
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogyby Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira on July 17, 2026 at 10:00 am
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.
- AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Reportby Ria Bhatia on July 16, 2026 at 11:00 pm
Explore Unit 42’s perspectives on AI’s impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.
- The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)by Unit 42 on July 15, 2026 at 11:00 pm
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Developmentby Chris Navarrete, Asher Davila and Doel Santos on July 15, 2026 at 10:00 am
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomwareby Matt Brady on July 10, 2026 at 10:00 pm
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
- Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflationby Bharath Nannaka and Pranay Kumar Chhaparwal on July 7, 2026 at 10:00 pm
A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.
- How We Added WebAuthn to a Browser-Based RDP Clientby Daniel Prizmant on July 2, 2026 at 10:00 pm
A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vectorby Keerthiraj Nagaraj, Diva-Oriane Marty, Beliz Kaleli and Oleksii Starov on July 1, 2026 at 1:00 am
Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.
- Threat Brief: Mitigating Large-Scale Credential Attacksby Andy Piazza on June 26, 2026 at 7:05 pm
We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors’ devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42.
- CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructureby Unit 42 on June 25, 2026 at 10:00 pm
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.
- OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threatby Shresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher and Oleksii Starov on June 23, 2026 at 10:00 pm
Unit 42’s analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.
- The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltrationby Yahav Festinger on June 22, 2026 at 10:00 pm
Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.
- Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCEby Ori Hadad on June 16, 2026 at 10:00 am
Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42.
- Inside the Modern SOC: The 72-Minute Raceby Sharon Maydar on June 15, 2026 at 11:00 pm
Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42’s AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42.





















