Visualização normal

Antes de ontemUnit 42

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

2 de Setembro de 2026, 07:00

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.

The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

31 de Agosto de 2026, 07:00

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

28 de Agosto de 2026, 19:00

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.

The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

25 de Agosto de 2026, 07:00

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.

The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

21 de Agosto de 2026, 20:00

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls

The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

Identity Abuse Through Trusted Communication Channels

20 de Agosto de 2026, 07:00

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.

The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

Kimwolf v7: An Evolution of the Kimwolf Botnet

11 de Agosto de 2026, 07:00

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.

The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

10 de Agosto de 2026, 19:00

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.

The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

Inside the Modern SOC: The Identity Front Door

7 de Agosto de 2026, 20:00

Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.

The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.

  • ✇Unit 42
  • ChainDrop: Inside a Self-Propagating npm Worm Unit 42
    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
     

ChainDrop: Inside a Self-Propagating npm Worm

6 de Agosto de 2026, 19:26

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

6 de Agosto de 2026, 07:00

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.

The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

Por:Xu Zou
4 de Agosto de 2026, 10:00

Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.

The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42.

Almost Half of Malware Samples Communicate Direct to IP

4 de Agosto de 2026, 09:50

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.

The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

3 de Agosto de 2026, 07:00

Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.

The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

31 de Julho de 2026, 07:00

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.

The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

30 de Julho de 2026, 07:00

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.

The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

  • ✇Unit 42
  • Russian Global Webmail Espionage Unit 42
    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
     

Russian Global Webmail Espionage

23 de Julho de 2026, 11:10

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials.

The post Russian Global Webmail Espionage appeared first on Unit 42.

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

17 de Julho de 2026, 07:00

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.

The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

16 de Julho de 2026, 20:00

Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report.

The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.

❌
❌