< ciso
brief />
Tag Banner

All news with #unit 42 tag

104 articles

Agentic AI and Kubernetes Operator Risks Explained

🔍 This Unit 42 report examines how Kubernetes operators’ reliance on highly privileged service accounts creates a critical security weak spot, and introduces OperTraitor, an open-source LLM-powered engine that analyzes operator RBAC configurations. The tool compares documented functionality to granted privileges and assigns a normalized risk score, revealing abandoned or overly permissive operators in registries like OperatorHub. Case studies include a High-severity CVE in IBM’s Turbonomic and an overly permissive Datadog operator configuration, and the article offers practical mitigation guidance such as verifying sources, enforcing namespace-scoped operators, and continuously auditing RBAC.
read more →

NetScaler zero-days exploited: urgent patch guidance

🔒 Unit 42 alerts that Citrix has reported active exploitation of two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on CVSS v4.0. The flaws enable unauthenticated remote code execution and a DTLS memory overflow that may cause RCE or DoS on NetScaler ADC and Gateway devices. Unit 42 urges immediate patching, system isolation, evidence preservation, and threat hunting while offering Incident Response assistance.
read more →

Unit 42 debunks three common cybersecurity myths

🔍 Unit 42 consultants identify three prevalent cybersecurity misconceptions undermining organizational defenses and prescribe corrective strategies. They warn against indiscriminate tool accumulation, which creates alert fatigue, feature underuse, and operational friction, and advocate auditing and consolidating existing platforms. Smaller organizations are reminded they remain attractive targets and should adopt an Assume Breach mindset. Finally, GRC must be treated as active defense rather than mere compliance, with robust RCM, framework alignment, and dedicated ownership.
read more →

Unit 42 Launches Continuous Frontier AI Defense

🔒 Unit 42 introduces Continuous Frontier AI Defense, an always-on service that combines offensive security expertise with Anthropic Mythos and OpenAI GPT cyber models to discover, validate, and remediate vulnerabilities across applications, identities, cloud, and network assets. The service uses proprietary multi-model harnesses and Zero Data Retention architectures to protect customer data while accelerating remediation and reducing exposure. It builds on prior Frontier AI offerings and is available worldwide via annual subscription.
read more →

Atomic macOS AMOS stealer activity snapshot

🔎 This Unit 42 analysis documents an AMOS stealer infection observed in a lab on Aug. 5, 2026, providing a snapshot of indicators seen at that time. The report outlines the infection chain beginning with a malicious webpage instructing copy/paste into Terminal, the Zsh scripts and Mach-O binaries used, and the persistence mechanisms under user Library directories. It also details collected artifacts, post‑infection HTTP POST traffic to C2 servers, and the frequent changes in indicators that characterize AMOS as an actively evolving threat.
read more →

Behavioral Clustering to Map Cloud Identities

🔍 This Unit 42 report describes a behavioral clustering model that maps functional cloud identities by extracting activity patterns from audit logs. The authors analyzed over 40,000 identities across 125 cloud environments to identify roles such as administrators, DevOps, backup services and security tooling. Using unsupervised techniques like UMAP and HDBSCAN, the model generates a behavioral map that aids scalable detection and SQ L-based heuristics for continuous visibility. The methodology is demonstrated on AWS CloudTrail and is extensible to other cloud and SaaS environments.
read more →

AI agents compress ransomware intrusion timelines

🛡️ Palo Alto Networks’ Unit 42 found an attacker using AI agents to traverse an enterprise network in under 10 hours, a process that could have taken human operators about two weeks. Agents conducted automated reconnaissance, searched code repositories for credentials, accessed secrets-management systems, and leveraged stolen cloud keys to abuse the victim’s AI services. The intrusion combined familiar MITRE ATT&CK techniques with agentic orchestration, highlighting the need for faster containment and stronger controls over non-human identities.
read more →

AI-Assisted Ransomware: Rapid Agentic Intrusion

🛡️ Unit 42 investigated an incident where a human operator used frontier AI agents to autonomously breach an enterprise network and execute a ransomware-style operation. The attack compressed weeks of tradecraft into under 10 hours by orchestrating >50 MITRE ATT&CK techniques via parallel LLM calls, structured agent communication, and AI-generated scripts. Agents performed reconnaissance, secrets harvesting, privilege takeover, CI/CD abuse, and hijacking of cloud AI endpoints to sustain post-compromise operations.
read more →

Spring Ring: Voice Phishing Through Collaboration Tools

🛡️ Between January and April 2026, Unit 42 uncovered a coordinated vishing operation—named Spring Ring—using external Microsoft Teams accounts to impersonate IT help desk staff. The attackers contacted over 150 employees across at least 10 companies and employed live voice calls to coerce victims into installing RMM tools or custom malware. Two distinct campaigns were observed: one delivering an obfuscated PowerShell RAT and another using tailored executables that attempted NTLM relay attacks against domain controllers.
read more →

AI-Enabled Malware: Prevalence, Detection, and Trends

🛡️ Palo Alto Networks Unit 42 analyzed 405 AI-integrated malware samples to measure real-world prevalence and detection efficacy. The dataset spans proof-of-concept code, security testing submissions, and AI-branded malware, but only 12 samples appeared on Cortex XDR-protected endpoints. Existing layered defenses — including behavioral analytics, WildFire sandboxing, and endpoint telemetry — detected and blocked all observed production samples.
read more →

Supply Chain Risks in the Modern SDLC

🔍 Unit 42 details how supply chain attacks have escalated, shifting adversaries from finished applications to the developer tooling and CI/CD pipelines that build software. The report examines incidents like ChainDrop, Axios, and Shai-Hulud to show how malicious preinstall scripts, account hijacks, and memory scraping steal credentials and self-propagate. It argues that SBOMs alone are insufficient and recommends continuous visibility, execution controls, ephemeral CI servers, and short-lived credentials to stop autonomous malware.
read more →

Unit 42 expands Frontier AI exposure analysis

🔍 Unit 42 is deploying advanced frontier AI cyber models in customer environments to find, validate, and help remediate meaningful attack paths. Through a partnership with OpenAI, Palo Alto Networks is integrating models like GPT-5.6 Daybreak into its Frontier AI Exposure Analysis to test exploitability, chain weaknesses, and prioritize fixes. Unit 42 combines model output with its offensive expertise and telemetry to validate findings and guide defenders.
read more →

Identity-Driven Attacks and SOC Response Trends

🔐 Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more →

AI Token Jacking: Rising Threat to Cloud AI Spend

🔒 Unit 42 details the surge in AI token jacking, where attackers steal API keys (tokens) to consume expensive AI model resources and sell access via proxy "transfer stations." The report explains token mechanics, attack vectors including stolen keys and malicious npm packages, and demonstrates how rapid abuse can cause catastrophic billing. It outlines mitigations such as spending limits, short-term tokens, AI gateways, and secure developer practices.
read more →

Report: Passkey weaknesses expose account takeover risks

🔒 A Palo Alto Networks Unit 42 report details how attackers can exploit onboarding, recovery and device-trust workflows to bypass passkey protections after compromising an endpoint. Analysts stress the underlying cryptography remains intact but warn implementations, synced passkeys and support processes create practical risks. Experts advise enforcing user verification, preferring device-bound authenticators and improving incident response.
read more →

Enterprise passkey risks from malware and weak processes

🔒 A Palo Alto Networks Unit 42 report details how malware on compromised endpoints can abuse onboarding, recovery and device-trust workflows to defeat passkey protections. The research outlines three attack categories—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that enable account takeover or mass extraction of synced passkeys. Experts emphasize these are post-compromise attacks that exploit implementation and procedural weaknesses rather than breaking the underlying cryptography. CISOs are advised to enforce user verification, prefer device-bound authenticators for sensitive accounts and tighten enrollment, recovery and sync policies.
read more →

XCSSET v40 Targets macOS Developers via Xcode

🛡️ Researchers at Unit 42 have uncovered a resurgence of the XCSSET macOS malware, now in version 40, which infects developers by injecting downloader scripts into compromised Xcode projects and GitHub repositories. The campaign was observed in two waves in mid-April and early May and introduces two new modules: a Chrome hijacker and a Telegram trojanizer. The malware employs enhanced evasion techniques, aggressively disables macOS protections, and propagates across Xcode projects when developers build infected code.
read more →

Frontier AI Drives a Surge in OSS Vulnerabilities

🛡️ Unit 42 reports that an autonomous agentic system called NOVA scanned 3,915 open-source projects and found 14,090 confirmed vulnerabilities in two months. The research shows 99.4% of findings were previously unreported and many were high or critical severity, demonstrating how frontier AI accelerates vulnerability discovery and compresses the time between disclosure and exploitation. The report highlights the need for rapid virtual patching, coordinated disclosure, and improved supply-chain and defensive practices.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

Unit 42 Threat Intelligence: Contextualized Defense

🔍 Security teams need intelligence that identifies what matters, when it matters, and what to do next. Unit 42 Threat Intelligence integrates proprietary research into the Cortex platform and offers analyst-driven services to deliver contextual, actionable insights. By correlating global visibility with each customer’s environment, it converts signals into prioritized detections, hunts and response actions. This approach addresses accelerated adversary behavior amplified by AI and shortens defenders’ reaction window.
read more →