<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Unit 42</title>
	<atom:link href="https://unit42.paloaltonetworks.com/feed/?v=2" rel="self" type="application/rss+xml"/>
	<link>https://unit42.paloaltonetworks.com/</link>
	<description>Palo Alto Networks</description>
	<lastBuildDate>Fri, 12 Jun 2026 19:32:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-Unit42-180x180-1.png</url>
	<title>Unit 42</title>
	<link>https://unit42.paloaltonetworks.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<itunes:explicit>no</itunes:explicit><itunes:subtitle>Palo Alto Networks</itunes:subtitle><item>
		<title>Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered</title>
		<link>https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/</link>
		
		<dc:creator><![CDATA[Chip Riley]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 22:00:14 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[macOS]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182477</guid>

					<description><![CDATA[<p>Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/">Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>3</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Listicle_Category_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>3</dcterms:extent>
		<enclosure length="620023" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Listicle_Category_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here. The post Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here. The post Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, digital forensics, macOS</itunes:keywords></item>
		<item>
		<title>Trust No Skill: Integrity Verification for AI Agent Supply Chains</title>
		<link>https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risks/</link>
		
		<dc:creator><![CDATA[Yuhao Wu, Tony Li and Hongliang Liu]]></dc:creator>
		<pubDate>Thu, 11 Jun 2026 10:00:24 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[credential exfiltration]]></category>
		<category><![CDATA[LLMs]]></category>
		<category><![CDATA[OpenClaw]]></category>
		<category><![CDATA[supply chain]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182196</guid>

					<description><![CDATA[<p>Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risks/">Trust No Skill: Integrity Verification for AI Agent Supply Chains</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>7</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_429594706-300x300.jpg</featuredImage>
		<dcterms:extent>7</dcterms:extent>
		<enclosure length="1464345" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_429594706.jpg"/>
			<itunes:explicit/><itunes:subtitle>Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains. The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42.</itunes:subtitle><itunes:summary>Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains. The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, AI agents, credential exfiltration, LLMs, OpenClaw, supply chain</itunes:keywords></item>
		<item>
		<title>Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility</title>
		<link>https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/</link>
		
		<dc:creator><![CDATA[Yahav Festinger]]></dc:creator>
		<pubDate>Tue, 09 Jun 2026 22:00:21 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AWS CloudTrail]]></category>
		<category><![CDATA[cloud logging]]></category>
		<category><![CDATA[defense evasion]]></category>
		<category><![CDATA[Google Cloud]]></category>
		<category><![CDATA[log poisoning]]></category>
		<category><![CDATA[log router]]></category>
		<category><![CDATA[log storage]]></category>
		<category><![CDATA[S3]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182090</guid>

					<description><![CDATA[<p>Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/">Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>12</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Cloud_cybersecurity_research_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>12</dcterms:extent>
		<enclosure length="1153636" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Cloud_cybersecurity_research_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion. The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion. The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, AWS CloudTrail, cloud logging, defense evasion, Google Cloud, log poisoning, log router, log storage, S3</itunes:keywords></item>
		<item>
		<title>Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257</title>
		<link>https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/</link>
		
		<dc:creator><![CDATA[Andy Piazza and Unit 42]]></dc:creator>
		<pubDate>Tue, 09 Jun 2026 14:05:42 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[CVE-2026-0257]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182026</guid>

					<description><![CDATA[<p>We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/">Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>3</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>3</dcterms:extent>
		<enclosure length="1486607" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42.</itunes:subtitle><itunes:summary>We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Vulnerabilities, CVE-2026-0257, vulnerability</itunes:keywords></item>
		<item>
		<title>When “Hi, This Is IT” Comes Through Microsoft Teams</title>
		<link>https://unit42.paloaltonetworks.com/microsoft-teams-phishing/</link>
		
		<dc:creator><![CDATA[Bill Batchelor]]></dc:creator>
		<pubDate>Mon, 08 Jun 2026 23:00:45 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Cloaked Ursa]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[social engineering]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182028</guid>

					<description><![CDATA[<p>Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/microsoft-teams-phishing/">When “Hi, This Is IT” Comes Through Microsoft Teams</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>6</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/02_Opinion_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>6</dcterms:extent>
		<enclosure length="807184" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/02_Opinion_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42.</itunes:subtitle><itunes:summary>Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, Cloaked Ursa, identity, phishing, social engineering</itunes:keywords></item>
		<item>
		<title>The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)</title>
		<link>https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 17:30:33 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Credential Harvesting]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[npm packages]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[worm propagation]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=179395</guid>

					<description><![CDATA[<p>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/">The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>23</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>23</dcterms:extent>
		<enclosure length="611893" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2) appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2) appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Malware, Credential Harvesting, GitHub, npm packages, obfuscation, payload, supply chain, worm propagation</itunes:keywords></item>
		<item>
		<title>Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor</title>
		<link>https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/</link>
		
		<dc:creator><![CDATA[Ido Asher, Noa Dekel and Tom Fakterman]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 10:00:31 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[CL-CRI-1089]]></category>
		<category><![CDATA[macOS]]></category>
		<category><![CDATA[malvertising]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181830</guid>

					<description><![CDATA[<p>Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/">Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>17</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Malware_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>17</dcterms:extent>
		<enclosure length="919617" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Malware_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42.</itunes:subtitle><itunes:summary>Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, CL-CRI-1089, macOS, malvertising</itunes:keywords></item>
		<item>
		<title>2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface</title>
		<link>https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/</link>
		
		<dc:creator><![CDATA[Justin Moore]]></dc:creator>
		<pubDate>Thu, 28 May 2026 10:00:53 +0000</pubDate>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Fiddling Scorpius]]></category>
		<category><![CDATA[Fighting Ursa]]></category>
		<category><![CDATA[Muddled Libra]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[QR Codes]]></category>
		<category><![CDATA[Razing Ursa]]></category>
		<category><![CDATA[typosquatting]]></category>
		<category><![CDATA[wiper]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181710</guid>

					<description><![CDATA[<p>The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/">2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>12</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>12</dcterms:extent>
		<enclosure length="954235" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42.</itunes:subtitle><itunes:summary>The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42.</itunes:summary><itunes:keywords>Cybercrime, General, Hacktivism, Insights, Threat Research, Fiddling Scorpius, Fighting Ursa, Muddled Libra, phishing, QR Codes, Razing Ursa, typosquatting, wiper</itunes:keywords></item>
		<item>
		<title>Out of the Crypt: The Evolving Cyber Extortion Economy</title>
		<link>https://unit42.paloaltonetworks.com/cyber-extortion-economy/</link>
		
		<dc:creator><![CDATA[Matt Brady and Justin Moore]]></dc:creator>
		<pubDate>Wed, 27 May 2026 22:00:46 +0000</pubDate>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Bling Libra]]></category>
		<category><![CDATA[Extortion]]></category>
		<category><![CDATA[Frontier AI]]></category>
		<category><![CDATA[Hazy Scorpius]]></category>
		<category><![CDATA[Scattered LAPSUS$ Hunters]]></category>
		<category><![CDATA[ShinyHunters]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[Telegram]]></category>
		<category><![CDATA[TGR-CRI-1135]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181604</guid>

					<description><![CDATA[<p>Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/cyber-extortion-economy/">Out of the Crypt: The Evolving Cyber Extortion Economy</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>8</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>8</dcterms:extent>
		<enclosure length="792432" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42.</itunes:summary><itunes:keywords>Cybercrime, General, Insights, Bling Libra, Extortion, Frontier AI, Hazy Scorpius, Scattered LAPSUS$ Hunters, ShinyHunters, supply chain, Telegram, TGR-CRI-1135</itunes:keywords></item>
		<item>
		<title>Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns</title>
		<link>https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Fri, 22 May 2026 13:00:42 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Actor Groups]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[AppDomainManager]]></category>
		<category><![CDATA[DLL Sideloading]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[MiniJunk]]></category>
		<category><![CDATA[MiniUpdate]]></category>
		<category><![CDATA[operation security]]></category>
		<category><![CDATA[RATs]]></category>
		<category><![CDATA[screening serpens]]></category>
		<category><![CDATA[social engineering]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181080</guid>

					<description><![CDATA[<p>Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/">Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>20</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-300x300.png</featuredImage>
		<dcterms:extent>20</dcterms:extent>
		<enclosure length="1112702" type="image/png" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2.png"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Actor Groups, Advanced Persistent Threat, AppDomainManager, DLL Sideloading, Iran, MiniJunk, MiniUpdate, operation security, RATs, screening serpens, social engineering</itunes:keywords></item>
		<item>
		<title>Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</title>
		<link>https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/</link>
		
		<dc:creator><![CDATA[Bill Batchelor and Eyal Rafian]]></dc:creator>
		<pubDate>Fri, 22 May 2026 10:00:24 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Curious Serpens]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[Microsoft Azure]]></category>
		<category><![CDATA[Microsoft graph API]]></category>
		<category><![CDATA[Midnight Blizzard]]></category>
		<category><![CDATA[MITRE]]></category>
		<category><![CDATA[ROADtools]]></category>
		<category><![CDATA[UTA0355]]></category>
		<category><![CDATA[Void Blizzard]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181397</guid>

					<description><![CDATA[<p>Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/">Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>14</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1-300x300.jpg</featuredImage>
		<dcterms:extent>14</dcterms:extent>
		<enclosure length="993522" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.</itunes:subtitle><itunes:summary>Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, Curious Serpens, Entra ID, Microsoft Azure, Microsoft graph API, Midnight Blizzard, MITRE, ROADtools, UTA0355, Void Blizzard</itunes:keywords></item>
		<item>
		<title>Tracking TamperedChef Clusters via Certificate and Code Reuse</title>
		<link>https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/</link>
		
		<dc:creator><![CDATA[Joseph Ganter]]></dc:creator>
		<pubDate>Wed, 20 May 2026 10:00:46 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Appsuite PDF]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[CL-CRI-1089]]></category>
		<category><![CDATA[CL-UNK-1090]]></category>
		<category><![CDATA[DocuFlex]]></category>
		<category><![CDATA[EvilAI]]></category>
		<category><![CDATA[malvertising]]></category>
		<category><![CDATA[RATs]]></category>
		<category><![CDATA[Remote Access Trojan]]></category>
		<category><![CDATA[TamperedChef]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180970</guid>

					<description><![CDATA[<p>Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/">Tracking TamperedChef Clusters via Certificate and Code Reuse</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>21</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/07_Security-Technology_Category_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>21</dcterms:extent>
		<enclosure length="791236" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/07_Security-Technology_Category_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Adware, Appsuite PDF, certificates, CL-CRI-1089, CL-UNK-1090, DocuFlex, EvilAI, malvertising, RATs, Remote Access Trojan, TamperedChef</itunes:keywords></item>
		<item>
		<title>Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files</title>
		<link>https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/</link>
		
		<dc:creator><![CDATA[Pranay Kumar Chhaparwal and Mark Lim]]></dc:creator>
		<pubDate>Fri, 15 May 2026 10:00:52 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[Cryptocurrency]]></category>
		<category><![CDATA[gremlin stealer]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[Telegram]]></category>
		<category><![CDATA[VirusTotal]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180614</guid>

					<description><![CDATA[<p>Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/">Gremlin Stealer&#039;s Evolved Tactics: Hiding in Plain Sight With Resource Files</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>7</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/02_Malware_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>7</dcterms:extent>
		<enclosure length="1869627" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/02_Malware_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer&amp;#039;s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer&amp;#039;s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, API, Cryptocurrency, gremlin stealer, obfuscation, payload, Telegram, VirusTotal</itunes:keywords></item>
		<item>
		<title>Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools</title>
		<link>https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/</link>
		
		<dc:creator><![CDATA[Stav Setty, Tom Fakterman and Shachar Roitman]]></dc:creator>
		<pubDate>Mon, 11 May 2026 22:00:43 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AD CS attacks]]></category>
		<category><![CDATA[certificate template]]></category>
		<category><![CDATA[certipy]]></category>
		<category><![CDATA[ESC1]]></category>
		<category><![CDATA[Fighting Ursa]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[shadow credentials]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180347</guid>

					<description><![CDATA[<p>Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/">Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>14</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/04_Malware_Category_1920x900-2-300x300.jpg</featuredImage>
		<dcterms:extent>14</dcterms:extent>
		<enclosure length="1400619" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/04_Malware_Category_1920x900-2.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Active Directory, AD CS attacks, certificate template, certipy, ESC1, Fighting Ursa, Microsoft, PKI, shadow credentials</itunes:keywords></item>
		<item>
		<title>Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution</title>
		<link>https://unit42.paloaltonetworks.com/captive-portal-zero-day/</link>
		
		<dc:creator><![CDATA[Justin Moore and Unit 42]]></dc:creator>
		<pubDate>Thu, 07 May 2026 00:00:53 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[CVE-2026-0300]]></category>
		<category><![CDATA[EarthWorm]]></category>
		<category><![CDATA[PAN-OS]]></category>
		<category><![CDATA[Remote Code Execution]]></category>
		<category><![CDATA[ReverseSocks5]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[zero-day]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180214</guid>

					<description><![CDATA[<p>Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/">Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>5</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-300x300.jpg</featuredImage>
		<dcterms:extent>5</dcterms:extent>
		<enclosure length="1645038" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Vulnerabilities, CVE-2026-0300, EarthWorm, PAN-OS, Remote Code Execution, ReverseSocks5, vulnerability, zero-day</itunes:keywords></item>
	</channel>
</rss>