Visualização normal

Antes de ontemUnit 42
  • ✇Unit 42
  • ChainDrop: Inside a Self-Propagating npm Worm Unit 42
    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
     

ChainDrop: Inside a Self-Propagating npm Worm

6 de Agosto de 2026, 19:26

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

6 de Agosto de 2026, 07:00

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.

The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

30 de Julho de 2026, 07:00

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.

The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

  • ✇Unit 42
  • Russian Global Webmail Espionage Unit 42
    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
     

Russian Global Webmail Espionage

23 de Julho de 2026, 11:10

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials.

The post Russian Global Webmail Espionage appeared first on Unit 42.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

25 de Junho de 2026, 19:00

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.

The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

18 de Agosto de 2026, 16:05

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks.

The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.

Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

5 de Junho de 2026, 11:05

We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257.

The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42.

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

22 de Maio de 2026, 10:00

Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns.

The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

15 de Julho de 2026, 20:00

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.

The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)

17 de Abril de 2026, 19:35

Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders.

The post Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) appeared first on Unit 42.

❌
❌