{"total":15,"items":[{"id":359,"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","original_title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","source_rating":null,"summary":"Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","type":"research","language":"en","published_at":"2026-09-30T20:00:04+00:00","severity":"middel","priority":37,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88772","cvss":9.5,"epss":0.01301,"epss_percentile":0.69413,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-88771","cvss":9.5,"epss":0.01063,"epss_percentile":0.63393,"in_kev":true,"kev_ransomware":false}],"cve_count":2,"in_kev":true,"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01301,"source_count":3,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":360,"title":"OperTraitors: How Kubernetes Operators Betray Your Security Posture","original_title":"OperTraitors: How Kubernetes Operators Betray Your Security Posture","source_rating":null,"summary":"We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/","type":"research","language":"en","published_at":"2026-09-29T10:00:48+00:00","severity":"laag","priority":0,"vendors":["Kubernetes"],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":361,"title":"3 Consulting Myths Debunked by Unit 42 Experts","original_title":"3 Consulting Myths Debunked by Unit 42 Experts","source_rating":null,"summary":"Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/3-consulting-myths-debunked-by-unit-42-experts/","type":"research","language":"en","published_at":"2026-09-25T23:00:28+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":362,"title":"From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies","original_title":"From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies","source_rating":null,"summary":"We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/","type":"research","language":"en","published_at":"2026-09-21T10:00:13+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":363,"title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","original_title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","source_rating":null,"summary":"Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","type":"research","language":"en","published_at":"2026-09-18T10:00:36+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":364,"title":"Inside the Modern SOC: Defending the Cross-Environment Pivot","original_title":"Inside the Modern SOC: Defending the Cross-Environment Pivot","source_rating":null,"summary":"Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/","type":"research","language":"en","published_at":"2026-09-17T22:00:33+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":365,"title":"Atomic macOS (AMOS) Stealer Activity","original_title":"Atomic macOS (AMOS) Stealer Activity","source_rating":null,"summary":"Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/","type":"research","language":"en","published_at":"2026-09-16T10:00:06+00:00","severity":"laag","priority":0,"vendors":["Apple"],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":366,"title":"Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection","original_title":"Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection","source_rating":null,"summary":"We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/","type":"research","language":"en","published_at":"2026-09-14T10:00:01+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":367,"title":"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE","original_title":"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE","source_rating":null,"summary":"Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces:…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/","type":"research","language":"en","published_at":"2026-09-10T10:00:43+00:00","severity":"laag","priority":0,"vendors":["Kubernetes"],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":368,"title":"Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure","original_title":"Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure","source_rating":null,"summary":"An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/","type":"research","language":"en","published_at":"2026-09-09T10:00:55+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":369,"title":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America","original_title":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America","source_rating":null,"summary":"Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/","type":"research","language":"en","published_at":"2026-09-03T10:00:58+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":370,"title":"An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation","original_title":"An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation","source_rating":null,"summary":"Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack:…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/","type":"research","language":"en","published_at":"2026-09-02T10:00:46+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":371,"title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","original_title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","source_rating":null,"summary":"Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/","type":"research","language":"en","published_at":"2026-08-31T10:00:36+00:00","severity":"laag","priority":0,"vendors":["Microsoft"],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":372,"title":"Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety","original_title":"Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety","source_rating":null,"summary":"New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/","type":"research","language":"en","published_at":"2026-08-28T22:00:07+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":373,"title":"The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution","original_title":"The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution","source_rating":null,"summary":"Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/","type":"research","language":"en","published_at":"2026-08-25T10:00:57+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null}]}