Visualização normal

Antes de ontemStream principal

That AI Extension Helping You Write Emails? It’s Reading Them First

Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser.

The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42.

  • ✇Cybersecurity News
  • The Malware Factory: Unmasking the 108-Package North Korean Siege on npm Ddos
    The post The Malware Factory: Unmasking the 108-Package North Korean Siege on npm appeared first on Daily CyberSecurity. Related posts: Lazarus Group’s Covert Supply Chain Attack: North Korean APT Poisons Open Source to Steal Developer Secrets North Korean APT Launches Massive npm Supply Chain Attack: Typosquatting & Fake Jobs Steal Crypto from Devs “Contagious” Code: North Korean Hackers Infiltrate Developer Workflows via Visual Studio Code
     

AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓

23 de Abril de 2026, 07:00

Unit 42は、マルチエージェントAIシステムがクラウド環境をどのように自律的に攻撃できるかを明らかにします。プロアクティブなセキュリティのための重要なインサイトと不可欠な教訓を学びます。

The post AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓 appeared first on Unit 42.

A Deep Dive Into Attempted Exploitation of CVE-2023-33538

16 de Abril de 2026, 19:00

CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware.

The post A Deep Dive Into Attempted Exploitation of CVE-2023-33538 appeared first on Unit 42.

  • ✇Unit 42
  • Cracks in the Bedrock: Agent God Mode Ori Hadad
    Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks. The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42.
     

Cracks in the Bedrock: Agent God Mode

8 de Abril de 2026, 19:00

Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks.

The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42.

Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox

7 de Abril de 2026, 19:00

Unit 42 uncovers critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, demonstrating DNS tunneling and credential exposure.

The post Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox appeared first on Unit 42.

Understanding Current Threats to Kubernetes Environments

6 de Abril de 2026, 19:00

Unit 42 uncovers escalating Kubernetes attacks, detailing how threat actors exploit identities and critical vulnerabilities to compromise cloud environments.

The post Understanding Current Threats to Kubernetes Environments appeared first on Unit 42.

When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications

3 de Abril de 2026, 19:00

Unit 42 research on multi-agent AI systems on Amazon Bedrock reveals new attack surfaces and prompt injection risks. Learn how to secure your AI applications.

The post When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications appeared first on Unit 42.

Double Agents: Exposing Security Blind Spots in GCP Vertex AI

31 de Março de 2026, 07:00

Unit 42 uncovers a "double agent" flaw in Google Cloud's Vertex AI, demonstrating how overprivileged AI agents can compromise cloud environments.

The post Double Agents: Exposing Security Blind Spots in GCP Vertex AI appeared first on Unit 42.

Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team

24 de Março de 2026, 19:00

Unit 42 identifies a recruitment phishing campaign targeting senior professionals via impersonation and fraudulent resume fees.

The post Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team appeared first on Unit 42.

Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication

23 de Março de 2026, 19:00

Explore Google’s synced passkey architecture. Unit 42 details its mechanisms, key management, and secure communication in passwordless systems."

The post Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication appeared first on Unit 42.

  • ✇Unit 42
  • Analyzing the Current State of AI Use in Malware Unit 42
    Unit 42 research explores how AI is currently used in malware, from superficial integrations to advanced decision-making, and its future impact. The post Analyzing the Current State of AI Use in Malware appeared first on Unit 42.
     

Analyzing the Current State of AI Use in Malware

19 de Março de 2026, 07:00

Unit 42 research explores how AI is currently used in malware, from superficial integrations to advanced decision-making, and its future impact.

The post Analyzing the Current State of AI Use in Malware appeared first on Unit 42.

Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models

17 de Março de 2026, 07:00

Unit 42 research unveils LLM guardrail fragility using genetic algorithm-inspired prompt fuzzing. Discover scalable evasion methods and critical GenAI security implications.

The post Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models appeared first on Unit 42.

  • ✇Unit 42
  • Boggy Serpens Threat Assessment Unit 42
    Iranian threat group Boggy Serpens' cyberespionage evolves with AI-enhanced malware and refined social engineering. Unit 42 details their persistent targeting. The post Boggy Serpens Threat Assessment appeared first on Unit 42.
     

Boggy Serpens Threat Assessment

16 de Março de 2026, 19:00

Iranian threat group Boggy Serpens' cyberespionage evolves with AI-enhanced malware and refined social engineering. Unit 42 details their persistent targeting.

The post Boggy Serpens Threat Assessment appeared first on Unit 42.

Auditing the Gatekeepers: Fuzzing "AI Judges" to Bypass Security Controls

10 de Março de 2026, 07:00

Unit 42 research reveals AI judges are vulnerable to stealthy prompt injection. Benign formatting symbols can bypass security controls.

The post Auditing the Gatekeepers: Fuzzing "AI Judges" to Bypass Security Controls appeared first on Unit 42.

❌
❌