Unit 42 Palo Alto Networks
- Trust No Skill: Integrity Verification for AI Agent Supply Chainsby Yuhao Wu, Tony Li and Hongliang Liu on June 11, 2026 at 10:00 am
Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains. The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42.
- Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibilityby Yahav Festinger on June 9, 2026 at 10:00 pm
Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion. The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42.
- Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257by Andy Piazza and Unit 42 on June 9, 2026 at 2:05 pm
We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42.
- When āHi, This Is ITā Comes Through Microsoft Teamsby Bill Batchelor on June 8, 2026 at 11:00 pm
Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization’s security. The post When āHi, This Is ITā Comes Through Microsoft Teams appeared first on Unit 42.
- The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)by Unit 42 on June 2, 2026 at 5:30 pm
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2) appeared first on Unit 42.
- Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoorby Ido Asher, Noa Dekel and Tom Fakterman on June 2, 2026 at 10:00 am
Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42.
- 2026 World Cup: Discussing The Worldās Biggest Gameās Attack Surfaceby Justin Moore on May 28, 2026 at 10:00 am
The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The Worldās Biggest Gameās Attack Surface appeared first on Unit 42.
- Out of the Crypt: The Evolving Cyber Extortion Economyby Matt Brady and Justin Moore on May 27, 2026 at 10:00 pm
Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42.
- Tracking Iranian APT Screening Serpensā 2026 Espionage Campaignsby Unit 42 on May 22, 2026 at 1:00 pm
Unit 42 details Screening Serpens’ use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpensā 2026 Espionage Campaigns appeared first on Unit 42.
- Paved With Intent: ROADtools and Nation-State Tactics in the Cloudby Bill Batchelor and Eyal Rafian on May 22, 2026 at 10:00 am
Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.
- Tracking TamperedChef Clusters via Certificate and Code Reuseby Joseph Ganter on May 20, 2026 at 10:00 am
Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.
- Gremlin Stealer’s Evolved Tactics: Hiding in Plain Sight With Resource Filesby Pranay Kumar Chhaparwal and Mark Lim on May 15, 2026 at 10:00 am
Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer’s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Toolsby Stav Setty, Tom Fakterman and Shachar Roitman on May 11, 2026 at 10:00 pm
Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.
- Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Executionby Justin Moore and Unit 42 on May 7, 2026 at 12:00 am
Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42.
- Copy Fail: What You Need to Know About the Most Severe Linux Threat in Yearsby Justin Moore on May 5, 2026 at 11:00 pm
Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42.




















