41554 blogs · [ { "id": "01a0e1d2-8f6f-70b0-9f9b-2bc624b7d424", "title": "3 Consulting Myths Debunked by Unit 42 Experts", "url": "https://unit42.paloaltonetworks.com/3-consulting-myths-debunked-by-unit-42-experts/", "published_at": "2026-09-25T23:00:28+00:00" }, { "id": "01a0d49e-2a97-728f-9ff1-5359681b8206", "title": "From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies", "url": "https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/", "published_at": "2026-09-21T10:00:13+00:00" }, { "id": "01a0d49e-2a97-728f-9ff1-53596897787b", "title": "A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity", "url": "https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/", "published_at": "2026-09-18T10:00:36+00:00" }, { "id": "01a0d49e-2a97-728f-9ff1-53596966b76b", "title": "Inside the Modern SOC: Defending the Cross-Environment Pivot", "url": "https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/", "published_at": "2026-09-17T22:00:33+00:00" }, { "id": "01a0d49e-2a97-728f-9ff1-535969ded0cd", "title": "Atomic macOS (AMOS) Stealer Activity", "url": "https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/", "published_at": "2026-09-16T10:00:06+00:00" }, { "id": "01a0d49e-2a97-728f-9ff1-53596a9d64d8", "title": "Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection", "url": "https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/", "published_at": "2026-09-14T10:00:01+00:00" }, { "id": "01a08c5a-a11f-706d-9ddb-5d214f1c51fc", "title": "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE", "url": "https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/", "published_at": "2026-09-10T10:00:43+00:00" }, { "id": "01a08c5a-a11f-706d-9ddb-5d21500454d2", "title": "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure", "url": "https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/", "published_at": "2026-09-09T10:00:55+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba494c0bc80", "title": "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America", "url": "https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/", "published_at": "2026-09-03T10:00:58+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba494ddd1e1", "title": "An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation", "url": "https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/", "published_at": "2026-09-02T10:00:46+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba4955db5f4", "title": "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams", "url": "https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/", "published_at": "2026-08-31T10:00:36+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba495fc9746", "title": "Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety", "url": "https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/", "published_at": "2026-08-28T22:00:07+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba49675bcbf", "title": "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution", "url": "https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/", "published_at": "2026-08-25T10:00:57+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba496a490d4", "title": "Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain", "url": "https://unit42.paloaltonetworks.com/sdlc-supply-chain/", "published_at": "2026-08-21T23:00:21+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba49731ef37", "title": "Identity Abuse Through Trusted Communication Channels", "url": "https://unit42.paloaltonetworks.com/communication-channel-identity-risks/", "published_at": "2026-08-20T10:00:25+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba4978768a4", "title": "Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)", "url": "https://unit42.paloaltonetworks.com/large-scale-credential-attacks/", "published_at": "2026-08-18T19:05:33+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba497d186bc", "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet", "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/", "published_at": "2026-08-11T10:00:16+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba4985d175a", "title": "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications", "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/", "published_at": "2026-08-10T22:00:02+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba4991e27e1", "title": "Inside the Modern SOC: The Identity Front Door", "url": "https://unit42.paloaltonetworks.com/soc-identity-front-door/", "published_at": "2026-08-07T23:00:01+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba499a33cc9", "title": "ChainDrop: Inside a Self-Propagating npm Worm", "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/", "published_at": "2026-08-06T22:26:39+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba49a09568e", "title": "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources", "url": "https://unit42.paloaltonetworks.com/ai-token-jacking/", "published_at": "2026-08-06T10:00:49+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba49adafc4a", "title": "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software", "url": "https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/", "published_at": "2026-08-04T13:00:11+00:00" }, { "id": "01a08219-ef63-73fe-ac7a-eba49b9f16e2", "title": "Almost Half of Malware Samples Communicate Direct to IP", "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/", "published_at": "2026-08-04T12:50:53+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573d8257b5b", "title": "Pass the Passkey: A Novel Attack Surface in Passwordless Authentication", "url": "https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/", "published_at": "2026-08-03T10:00:35+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573d860154b", "title": "The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version", "url": "https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/", "published_at": "2026-07-31T10:00:18+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573d8c31840", "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks", "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/", "published_at": "2026-07-30T10:00:52+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573d8d3412d", "title": "Russian Global Webmail Espionage", "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/", "published_at": "2026-07-23T14:10:53+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573d8ff73bd", "title": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy", "url": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/", "published_at": "2026-07-17T10:00:24+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573d9e0bb3f", "title": "AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report", "url": "https://unit42.paloaltonetworks.com/ai-insights-incident-response-report/", "published_at": "2026-07-16T23:00:59+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573daad933b", "title": "The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)", "url": "https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/", "published_at": "2026-07-15T23:00:33+00:00" }, { "id": "01a0d49d-2999-722a-8ea9-1573db7a15e2", "title": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development", "url": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/", "published_at": "2026-07-15T10:00:54+00:00" }, { "id": "01a0d4a0-4835-7159-ae22-f2ac8b4c4dc7", "title": "No Manners Here: The Ruthless Rise of The Gentlemen Ransomware", "url": "https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/", "published_at": "2026-07-10T22:00:39+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb027513b", "title": "Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation", "url": "https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/", "published_at": "2026-07-07T22:00:21+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb05063b6", "title": "How We Added WebAuthn to a Browser-Based RDP Client", "url": "https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/", "published_at": "2026-07-02T22:00:39+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb1020048", "title": "Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector", "url": "https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/", "published_at": "2026-07-01T01:00:11+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb1e8c5e8", "title": "CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure", "url": "https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/", "published_at": "2026-06-25T22:00:52+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb2a89765", "title": "OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat", "url": "https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/", "published_at": "2026-06-23T22:00:51+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb354e32a", "title": "The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration", "url": "https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/", "published_at": "2026-06-22T22:00:04+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb387077b", "title": "Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE", "url": "https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/", "published_at": "2026-06-16T10:00:29+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb40f3bf4", "title": "Inside the Modern SOC: The 72-Minute Race", "url": "https://unit42.paloaltonetworks.com/soc-72-minute-race/", "published_at": "2026-06-15T23:00:19+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb46f3bee", "title": "Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered", "url": "https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/", "published_at": "2026-06-12T22:00:14+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb4e5cfd6", "title": "Trust No Skill: Integrity Verification for AI Agent Supply Chains", "url": "https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risks/", "published_at": "2026-06-11T10:00:24+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb572ba22", "title": "Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility", "url": "https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/", "published_at": "2026-06-09T22:00:21+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb5f33eb8", "title": "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257", "url": "https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/", "published_at": "2026-06-09T14:05:42+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb613b9c8", "title": "When “Hi, This Is IT” Comes Through Microsoft Teams", "url": "https://unit42.paloaltonetworks.com/microsoft-teams-phishing/", "published_at": "2026-06-08T23:00:45+00:00" }, { "id": "01a0d4a0-4836-7245-96fd-928cb6aa8283", "title": "Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor", "url": "https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/", "published_at": "2026-06-02T10:00:31+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eaf0ca772", "title": "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface", "url": "https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/", "published_at": "2026-05-28T10:00:53+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eaf43a41c", "title": "Out of the Crypt: The Evolving Cyber Extortion Economy", "url": "https://unit42.paloaltonetworks.com/cyber-extortion-economy/", "published_at": "2026-05-27T22:00:46+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb0069726", "title": "Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns", "url": "https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/", "published_at": "2026-05-22T13:00:42+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb09bfa20", "title": "Paved With Intent: ROADtools and Nation-State Tactics in the Cloud", "url": "https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/", "published_at": "2026-05-22T10:00:24+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb11f6c3e", "title": "Tracking TamperedChef Clusters via Certificate and Code Reuse", "url": "https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/", "published_at": "2026-05-20T10:00:46+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb15e9714", "title": "Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files", "url": "https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/", "published_at": "2026-05-15T10:00:52+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb1d3f97a", "title": "Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools", "url": "https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/", "published_at": "2026-05-11T22:00:43+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb210d22c", "title": "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution", "url": "https://unit42.paloaltonetworks.com/captive-portal-zero-day/", "published_at": "2026-05-07T00:00:53+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb25ea460", "title": "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years", "url": "https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/", "published_at": "2026-05-05T23:00:33+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb3557210", "title": "Essential Data Sources for Detection Beyond the Endpoint", "url": "https://unit42.paloaltonetworks.com/detection-beyond-the-endpoint/", "published_at": "2026-05-01T23:00:13+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb446d215", "title": "That AI Extension Helping You Write Emails? It’s Reading Them First", "url": "https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/", "published_at": "2026-04-30T22:00:57+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb4c76dc1", "title": "TGR-STA-1030: New Activity in Central and South America", "url": "https://unit42.paloaltonetworks.com/new-activity-central-south-america/", "published_at": "2026-04-24T20:30:19+00:00" }, { "id": "01a0d4a2-34e6-73ae-8a47-696eb57f3874", "title": "Frontier AI and the Future of Defense: Your Top Questions Answered", "url": "https://unit42.paloaltonetworks.com/frontier-ai-top-questions-answered/", "published_at": "2026-04-23T20:45:50+00:00" }, { "id": "01a0d4a2-34e7-7061-b667-22190789e039", "title": "Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System", "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/", "published_at": "2026-04-23T10:00:31+00:00" }, { "id": "01a0d4a2-34e7-7061-b667-2219082bbb37", "title": "When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks", "url": "https://unit42.paloaltonetworks.com/air-snitch-enterprise-wireless-attacks/", "published_at": "2026-04-22T10:00:22+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b90c37aea", "title": "Fracturing Software Security With Frontier AI Models", "url": "https://unit42.paloaltonetworks.com/ai-software-security-risks/", "published_at": "2026-04-20T10:00:14+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b9189946a", "title": "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)", "url": "https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/", "published_at": "2026-04-17T22:35:07+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b9249398d", "title": "A Deep Dive Into Attempted Exploitation of CVE-2023-33538", "url": "https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/", "published_at": "2026-04-16T22:00:13+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b9266b1ab", "title": "Cracks in the Bedrock: Agent God Mode", "url": "https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-mode/", "published_at": "2026-04-08T22:00:51+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b928f5a28", "title": "Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox", "url": "https://unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-mode/", "published_at": "2026-04-07T22:00:11+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b92b83f93", "title": "Understanding Current Threats to Kubernetes Environments", "url": "https://unit42.paloaltonetworks.com/modern-kubernetes-threats/", "published_at": "2026-04-06T22:00:08+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b9363b63e", "title": "When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications", "url": "https://unit42.paloaltonetworks.com/amazon-bedrock-multiagent-applications/", "published_at": "2026-04-03T22:00:38+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b93f7d3be", "title": "Threat Brief: Widespread Impact of the Axios Supply Chain Attack", "url": "https://unit42.paloaltonetworks.com/axios-supply-chain-attack/", "published_at": "2026-04-01T18:30:10+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b94011a1c", "title": "Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure", "url": "https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/", "published_at": "2026-03-31T21:00:39+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b94bee4d9", "title": "Double Agents: Exposing Security Blind Spots in GCP Vertex AI", "url": "https://unit42.paloaltonetworks.com/double-agents-vertex-ai/", "published_at": "2026-03-31T10:00:56+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b9501fcb2", "title": "Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government", "url": "https://unit42.paloaltonetworks.com/espionage-campaigns-target-se-asian-government-org/", "published_at": "2026-03-26T22:00:32+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b95f2ace2", "title": "Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team", "url": "https://unit42.paloaltonetworks.com/phishing-attackers-pose-as-panw-recruiters/", "published_at": "2026-03-24T22:00:12+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b96dafc05", "title": "Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication", "url": "https://unit42.paloaltonetworks.com/passwordless-authentication/", "published_at": "2026-03-23T22:00:42+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b97493a69", "title": "Who’s Really Shopping? Retail Fraud in the Age of Agentic AI", "url": "https://unit42.paloaltonetworks.com/retail-fraud-agentic-ai/", "published_at": "2026-03-20T23:00:52+00:00" }, { "id": "01a0d4a3-14c2-7331-a2c2-b45b98217f9f", "title": "Analyzing the Current State of AI Use in Malware", "url": "https://unit42.paloaltonetworks.com/ai-use-in-malware/", "published_at": "2026-03-19T10:00:01+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12717c8b3d67", "title": "Navigating Security Tradeoffs of AI Agents", "url": "https://unit42.paloaltonetworks.com/navigating-security-tradeoffs-ai-agents/", "published_at": "2026-03-18T23:00:28+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12717ca1a007", "title": "Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models", "url": "https://unit42.paloaltonetworks.com/genai-llm-prompt-fuzzing/", "published_at": "2026-03-17T10:00:38+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12717d54a463", "title": "Boggy Serpens Threat Assessment", "url": "https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/", "published_at": "2026-03-16T22:00:57+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12717d7ab318", "title": "Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization", "url": "https://unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats/", "published_at": "2026-03-16T19:15:43+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12717e6df18f", "title": "Insights: Increased Risk of Wiper Attacks", "url": "https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/", "published_at": "2026-03-12T22:10:00+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12717f1b0c8e", "title": "Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia", "url": "https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/", "published_at": "2026-03-12T22:00:57+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127180064287", "title": "Auditing the Gatekeepers: Fuzzing \"AI Judges\" to Bypass Security Controls", "url": "https://unit42.paloaltonetworks.com/fuzzing-ai-judges-security-bypass/", "published_at": "2026-03-10T10:00:29+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127181014331", "title": "An Investigation Into Years of Undetected Operations Targeting High-Value Sectors", "url": "https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/", "published_at": "2026-03-06T11:00:35+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127181245ff3", "title": "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild", "url": "https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/", "published_at": "2026-03-03T11:00:30+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127181a97b25", "title": "Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel", "url": "https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/", "published_at": "2026-03-02T11:00:36+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127181eb5b54", "title": "Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security", "url": "https://unit42.paloaltonetworks.com/ot-edge-security/", "published_at": "2026-02-24T14:00:40+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127182d07247", "title": "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)", "url": "https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/", "published_at": "2026-02-19T23:00:55+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-12718366cd87", "title": "Critical Vulnerabilities in Ivanti EPMM Exploited", "url": "https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/", "published_at": "2026-02-17T20:35:02+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-1271841d751d", "title": "Phishing on the Edge of the Web and Mobile Using QR Codes", "url": "https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/", "published_at": "2026-02-13T23:00:48+00:00" }, { "id": "01a0d4a4-941a-7270-8f8a-127184ac6410", "title": "Nation-State Actors Exploit Notepad++ Supply Chain", "url": "https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/", "published_at": "2026-02-11T23:00:54+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec18cd46b5", "title": "A Peek Into Muddled Libra’s Operational Playbook", "url": "https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/", "published_at": "2026-02-10T23:00:41+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec19ae9970", "title": "Novel Technique to Detect Cloud Threat Actor Operations", "url": "https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging/", "published_at": "2026-02-06T23:00:02+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1a1e438c", "title": "The Shadow Campaigns: Uncovering Global Espionage", "url": "https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/", "published_at": "2026-02-05T11:00:10+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1a57efc7", "title": "Why Smart People Fall For Phishing Attacks", "url": "https://unit42.paloaltonetworks.com/psychology-of-phishing/", "published_at": "2026-02-04T00:00:43+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1a72d416", "title": "Privileged File System Vulnerability Present in a SCADA System", "url": "https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/", "published_at": "2026-01-30T23:00:01+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1a7e75b5", "title": "Understanding the Russian Cyberthreat to the 2026 Winter Olympics", "url": "https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/", "published_at": "2026-01-29T21:30:47+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1b5a205c", "title": "Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense", "url": "https://unit42.paloaltonetworks.com/cta-9th-anniversary/", "published_at": "2026-01-24T00:00:53+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1b60ab97", "title": "The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time", "url": "https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/", "published_at": "2026-01-22T11:00:22+00:00" }, { "id": "01a0d4a5-1a4e-7032-821a-20ec1b68d7ee", "title": "DNS OverDoS: Are Private Endpoints Too Private?", "url": "https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/", "published_at": "2026-01-20T17:23:33+00:00" } ] posts Claim your blog
Back to Unit 42
Blog · corpus.blog/blogs/unit42.paloaltonetworks.com/posts

Unit 42

unit42.paloaltonetworks.com

2026