Palo Alto Networks Unit 42

paloaltonetworks.com

Imported from official source

Palo Alto Networks' threat research group.

Type
Company
Scope
US · national
Website
paloaltonetworks.com
Feed
Atom

Publications 19

  1. OperTraitors: How Kubernetes Operators Betray Your Security Posture

    We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray ...

  2. Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

    Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-...

    Cybersecurity 2 versions
  3. 3 Consulting Myths Debunked by Unit 42 Experts

    Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked...

  4. From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies

    We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neu...

  5. A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

    Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfo...

  6. Inside the Modern SOC: Defending the Cross-Environment Pivot

    Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending ...

  7. Atomic macOS (AMOS) Stealer Activity

    Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared ...

  8. Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

    We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Beh...

  9. The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

    Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exp...

  10. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behin...

  11. Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

    Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use ...

  12. An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

    Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Insi...

  13. Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

    Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campa...

  14. Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

    New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for th...

    AI
  15. The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

    Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware Augus...

  16. Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

    Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Over...

  17. Identity Abuse Through Trusted Communication Channels

    Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communicati...

  18. Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

    In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks....

  19. Kimwolf v7: An Evolution of the Kimwolf Botnet

    Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appea...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.