The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.

We identified a coordinated campaign of 10 browser #extensions disguised as browser games. On installation, extension names resolve through fragmented translation keys and runtime #impersonates crypto wallets with a remote kill switch. Details at bit.ly/3VzIV5o
5
20
2,553
We examined how AWS secures exposed credentials through managed policies. We tracked policy updates against new cloud threats, tested the GitHub secret scanning integration, and outlined practical logging strategies to detect quarantine events: bit.ly/4yQVjfD
2
7
17
2,386
Unit 42 continues to track network infrastructure that is likely associated with Com-affiliated threat actors. Two of these domains are likely being used to target organizations operating across a wide array of industries. Details at bit.ly/3THZQCi
2
11
36
6,295
Unit 42 continues to track network infrastructure likely associated with Com-affiliated threat actors. One of these domains (my-passkeys[.]com) is likely being used to target organizations operating with the healthcare and pharmaceutical sectors. Details: bit.ly/4yUh667
3
20
67
6,807
In testing AWS AgentCore Harness default configurations, we found prompt injection can leverage the shell tool to access plaintext credentials in process memory. Operators can mitigate these risks by restricting default tools and enforcing least privilege: bit.ly/4h7sGVK
3
9
11
2,868
We found an active indirect prompt injection campaign targeting AI ad review systems. 10 domains, one of which was ranked #1 in web search results, embed hidden payloads impersonating a popular advertiser compliance to bypass ad review. Details at bit.ly/46K6vij
5
14
46
4,476
🚨 Armed with AI, threat actors now weaponize vulnerabilities in minutes. Human-speed defense can’t keep up. Meet @Unit42_Intel Continuous Frontier AI Defense: leading frontierAI models + elite security experts to find, validate, and fix exposures. Giving the advantage back to defenders. bit.ly/4rvQWo8
3
3
13
5,484
Identifying functional cloud roles is difficult when attackers obscure identity behavior. We mapped 40,000 identities across 125 environments with unsupervised machine learning algorithms to deliver continuous visibility in standard SQL: bit.ly/4xv5YvD
2
3
10
3,471
We documented P2PInfect in 2023 spreading via a Lua sandbox escape. In Mar–Aug 2026, our honeypots saw 692 attacking IPs and 363 C2s push the same worm via Redis misconfig: SLAVEOF to a rogue master, and RDB writes planting a crontab entry and an SSH key: bit.ly/3VDGdvC
1
5
18
3,536
A sustained ClickFix campaign has compromised 350+ websites on a leading CMS platform since August. The attack abuses a free CDN, hosting and rotating malicious payloads across public repos. Details at bit.ly/4rCmBEt
2
28
97
7,600
A compromised regional news outlet’s WordPress site is using malicious JS to serve #ClickFix prompts, ultimately delivering a ConfuserEx-encrypted #StealC payload. One observed infection chain routed a targeted user via a local library's proxy. Details at: bit.ly/4ran9B3
2
23
52
6,335
While we have some indicators that StealC is associated with this infection chain, we have not yet confirmed.
2
6
1,842
Attackers with root access on a compromised Kubernetes node can manipulate control group metadata to bypass SPIFFE and SPIRE open standard workload identity controls. This prompts systems to issue credentials for co-located app: bit.ly/4iVSIMO
4
8
21
3,697
NeuralOverride is a Cyrillic Python RAT using Telegram for C2 and integrating the #OpenRouter LLM for autonomous attack planning. It includes #SCADA tasking stubs referencing a missing scada_commander.py module. The 5-build family evolved over one month: bit.ly/4j5xRXs
2
14
58
5,786
ZionSiphon v4 is a #Rust rewrite of the OT (ICS) sabotage tool targeting Israeli water and #desalination systems. Adds USB propagation and Modbus write attempts. Details at bit.ly/4hucnlP
2
10
47
4,927
We tracked a cybercrime pay per install network reaching enterprise endpoints by targeting young gamers on YouTube and corporate users via SEO poisoning. A single custom loader deployed multiple malware strains across networks: bit.ly/4r6F7Ew
1
4
34
4,820
We continue to actively track newly created infrastructure likely associated with Com-affiliated threat actors that are used as part of their data theft and extortion campaigns. We've identified 17 FQDNs since our last post on Aug. 28th. Details on GitHub: bit.ly/4d3JdYc
2
29
89
7,637
We saw attackers using commercial AI tools, targeting systems in transportation and financial sectors in Latin America. They used self-hosted NextChat to fix collection errors, and exposed their AI-generated scripts. Read our analysis for details: bit.ly/4xI8XS6
2
4
23
3,972
We investigated a breach where autonomous AI agents executed an intrusion in under 10 hours, compressing weeks of tradecraft. The actor mapped networks, seized root credentials and left an AI-generated report. Explore our full investigation: bit.ly/4iKWXe2
7
40
181
18,725