Unit 42 Palo Alto Networks
- Gremlin Stealer’s Evolved Tactics: Hiding in Plain Sight With Resource Filesby Pranay Kumar Chhaparwal and Mark Lim on May 15, 2026 at 10:00 am
Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer’s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Toolsby Stav Setty, Tom Fakterman and Shachar Roitman on May 11, 2026 at 10:00 pm
Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.
- Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Executionby Justin Moore and Unit 42 on May 7, 2026 at 12:00 am
Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42.
- Copy Fail: What You Need to Know About the Most Severe Linux Threat in Yearsby Justin Moore on May 5, 2026 at 11:00 pm
Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42.
- The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1)by Unit 42 on May 2, 2026 at 12:10 am
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) appeared first on Unit 42.
- Essential Data Sources for Detection Beyond the Endpointby Corey Berman and Matt Gayford on May 1, 2026 at 11:00 pm
Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42.
- That AI Extension Helping You Write Emails? It’s Reading Them Firstby Shresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher, Oleksii Starov, Qinge Xie and Fang Liu on April 30, 2026 at 10:00 pm
Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42.
- TGR-STA-1030: New Activity in Central and South Americaby Unit 42 on April 24, 2026 at 8:30 pm
Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. The post TGR-STA-1030: New Activity in Central and South America appeared first on Unit 42.
- Frontier AI and the Future of Defense: Your Top Questions Answeredby Sam Rubin on April 23, 2026 at 8:45 pm
What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking. The post Frontier AI and the Future of Defense: Your Top Questions Answered appeared first on Unit 42.
- Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent Systemby Yahav Festinger and Chen Doytshman on April 23, 2026 at 10:00 am
Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments. Learn critical insights and vital lessons for proactive security. The post Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System appeared first on Unit 42.
- When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacksby Emmanuel Zhou, Adam Robbie, Rick Wyble, Zhutian Liu, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy and Mathy Vanhoef on April 22, 2026 at 10:00 am
Unit 42 research reveals AirSnitch attacks bypass WPA2/3 Wi-Fi encryption and client isolation, exposing critical infrastructure vulnerabilities. The post When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks appeared first on Unit 42.
- Fracturing Software Security With Frontier AI Modelsby Andy Piazza on April 20, 2026 at 10:00 am
Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42.
- Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)by Unit 42 on April 17, 2026 at 10:35 pm
Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders. The post Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) appeared first on Unit 42.
- A Deep Dive Into Attempted Exploitation of CVE-2023-33538by Asher Davila, Malav Vyas and Chris Navarrete on April 16, 2026 at 10:00 pm
CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware. The post A Deep Dive Into Attempted Exploitation of CVE-2023-33538 appeared first on Unit 42.
- Cracks in the Bedrock: Agent God Modeby Ori Hadad on April 8, 2026 at 10:00 pm
Unit 42 reveals “Agent God Mode” in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks. The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42.





















