<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Unit 42</title>
	<atom:link href="https://unit42.paloaltonetworks.com/feed/?v=2" rel="self" type="application/rss+xml"/>
	<link>https://unit42.paloaltonetworks.com/</link>
	<description>Palo Alto Networks</description>
	<lastBuildDate>Mon, 28 Sep 2026 23:18:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-Unit42-180x180-1.png</url>
	<title>Unit 42</title>
	<link>https://unit42.paloaltonetworks.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<itunes:explicit>no</itunes:explicit><itunes:subtitle>Palo Alto Networks</itunes:subtitle><item>
		<title>OperTraitors: How Kubernetes Operators Betray Your Security Posture</title>
		<link>https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/</link>
		
		<dc:creator><![CDATA[Lior Yakim]]></dc:creator>
		<pubDate>Tue, 29 Sep 2026 10:00:48 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=187565</guid>

					<description><![CDATA[<p>We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/">OperTraitors: How Kubernetes Operators Betray Your Security Posture</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>8</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_652069707-1-300x300.jpg</featuredImage>
		<dcterms:extent>8</dcterms:extent>
		<enclosure length="1523818" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_652069707-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42.</itunes:subtitle><itunes:summary>We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, AI, AI agents, API, GitHub, identity, Vulnerabilities</itunes:keywords></item>
		<item>
		<title>Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild</title>
		<link>https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 15:02:04 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Citrix Netscaler]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[Remote Code Execution]]></category>
		<category><![CDATA[zero-day]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=187874</guid>

					<description><![CDATA[<p>Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/">Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>2</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/06_Vulnerabilities_1920x900-5-300x300.jpg</featuredImage>
		<dcterms:extent>2</dcterms:extent>
		<enclosure length="1645038" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/06_Vulnerabilities_1920x900-5.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Vulnerabilities, Citrix Netscaler, denial of service, Remote Code Execution, zero-day</itunes:keywords></item>
		<item>
		<title>3 Consulting Myths Debunked by Unit 42 Experts</title>
		<link>https://unit42.paloaltonetworks.com/3-consulting-myths-debunked-by-unit-42-experts/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 23:00:28 +0000</pubDate>
				<category><![CDATA[Insights]]></category>
		<category><![CDATA[Myth Busting]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[Unit 42 Incident Response Report]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=187627</guid>

					<description><![CDATA[<p>Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/3-consulting-myths-debunked-by-unit-42-experts/">3 Consulting Myths Debunked by Unit 42 Experts</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>4</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/01_Listicle_Category_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>4</dcterms:extent>
		<enclosure length="547369" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/01_Listicle_Category_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42.</itunes:summary><itunes:keywords>Insights, Myth Busting, AI, privilege escalation, Unit 42 Incident Response Report</itunes:keywords></item>
		<item>
		<title>From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies</title>
		<link>https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/</link>
		
		<dc:creator><![CDATA[Margaret Kelley]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 10:00:13 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[AWS CloudTrail]]></category>
		<category><![CDATA[bedrock]]></category>
		<category><![CDATA[cloud compute]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[JSON]]></category>
		<category><![CDATA[logging]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186917</guid>

					<description><![CDATA[<p>We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/">From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>14</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Cloud_cybersecurity_research_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>14</dcterms:extent>
		<enclosure length="1339704" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Cloud_cybersecurity_research_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42.</itunes:subtitle><itunes:summary>We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, AWS, AWS CloudTrail, bedrock, cloud compute, GitHub, JSON, logging</itunes:keywords></item>
		<item>
		<title>A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity</title>
		<link>https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/</link>
		
		<dc:creator><![CDATA[Niv Rabin]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 10:00:36 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[exfiltration]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Sandbox]]></category>
		<category><![CDATA[shell tool]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=187347</guid>

					<description><![CDATA[<p>Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/">A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>16</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/03_Cloud_cybersecurity_research_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>16</dcterms:extent>
		<enclosure length="1441564" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/03_Cloud_cybersecurity_research_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.</itunes:subtitle><itunes:summary>Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, Agentic AI, AWS, Cloud, exfiltration, IAM, Sandbox, shell tool</itunes:keywords></item>
		<item>
		<title>Inside the Modern SOC: Defending the Cross-Environment Pivot</title>
		<link>https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/</link>
		
		<dc:creator><![CDATA[Sharon Maydar]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 22:00:33 +0000</pubDate>
				<category><![CDATA[Inside the Modern SOC]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[attack surface]]></category>
		<category><![CDATA[Unit 42 Incident Response Report]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=187343</guid>

					<description><![CDATA[<p>Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/">Inside the Modern SOC: Defending the Cross-Environment Pivot</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>3</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/01_Myth-Busting_Overview_1920x900_Resized-300x300.jpg</featuredImage>
		<dcterms:extent>3</dcterms:extent>
		<enclosure length="1518417" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/01_Myth-Busting_Overview_1920x900_Resized.jpg"/>
			<itunes:explicit/><itunes:subtitle>Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.</itunes:subtitle><itunes:summary>Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.</itunes:summary><itunes:keywords>Inside the Modern SOC, Insights, AI, attack surface, Unit 42 Incident Response Report</itunes:keywords></item>
		<item>
		<title>Atomic macOS (AMOS) Stealer Activity</title>
		<link>https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/</link>
		
		<dc:creator><![CDATA[Bradley Duncan]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 10:00:06 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[macOS]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Unit 42]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=187032</guid>

					<description><![CDATA[<p>Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/">Atomic macOS (AMOS) Stealer Activity</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>7</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>7</dcterms:extent>
		<enclosure length="1173612" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.</itunes:subtitle><itunes:summary>Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, Malware, macOS, threat intelligence, Unit 42</itunes:keywords></item>
		<item>
		<title>Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection</title>
		<link>https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/</link>
		
		<dc:creator><![CDATA[Osher Jacob]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 10:00:01 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AWS CloudTrail]]></category>
		<category><![CDATA[cloud detection]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[SQL]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186821</guid>

					<description><![CDATA[<p>We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/">Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>12</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Cloud_cybersecurity_research_Overview_1920x900-2-300x300.jpg</featuredImage>
		<dcterms:extent>12</dcterms:extent>
		<enclosure length="1163529" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Cloud_cybersecurity_research_Overview_1920x900-2.jpg"/>
			<itunes:explicit/><itunes:subtitle>We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.</itunes:subtitle><itunes:summary>We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, AWS CloudTrail, cloud detection, DevOps, IAM, SQL</itunes:keywords></item>
		<item>
		<title>The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE</title>
		<link>https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/</link>
		
		<dc:creator><![CDATA[Eviatar Garzi]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 10:00:43 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[cryptographic]]></category>
		<category><![CDATA[JSON]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[node]]></category>
		<category><![CDATA[SPIFFE]]></category>
		<category><![CDATA[SPIRE]]></category>
		<category><![CDATA[spoofing]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186732</guid>

					<description><![CDATA[<p>Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/">The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>11</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>11</dcterms:extent>
		<enclosure length="736161" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.</itunes:subtitle><itunes:summary>Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, API, cryptographic, JSON, Linux, node, SPIFFE, SPIRE, spoofing</itunes:keywords></item>
		<item>
		<title>Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure</title>
		<link>https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/</link>
		
		<dc:creator><![CDATA[Rem Dudas]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 10:00:55 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[ARKTunnel]]></category>
		<category><![CDATA[C2]]></category>
		<category><![CDATA[CL-CRI-1171]]></category>
		<category><![CDATA[Docro Hijacker]]></category>
		<category><![CDATA[pay-per-install]]></category>
		<category><![CDATA[payload]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186615</guid>

					<description><![CDATA[<p>An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/">Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>18</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-300x300.jpg</featuredImage>
		<dcterms:extent>18</dcterms:extent>
		<enclosure length="1400619" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6.jpg"/>
			<itunes:explicit/><itunes:subtitle>An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.</itunes:subtitle><itunes:summary>An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, ARKTunnel, C2, CL-CRI-1171, Docro Hijacker, pay-per-install, payload</itunes:keywords></item>
		<item>
		<title>Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America</title>
		<link>https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/</link>
		
		<dc:creator><![CDATA[Reese Lewis and Sara McBroom]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 10:00:58 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[CL-CRI-1131]]></category>
		<category><![CDATA[CL-CRI-1163]]></category>
		<category><![CDATA[Claude code]]></category>
		<category><![CDATA[financial sector]]></category>
		<category><![CDATA[NextChat]]></category>
		<category><![CDATA[Shipping and Transportation]]></category>
		<category><![CDATA[SOCKS5]]></category>
		<category><![CDATA[SockTz]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186340</guid>

					<description><![CDATA[<p>Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/">Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>8</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-300x300.jpg</featuredImage>
		<dcterms:extent>8</dcterms:extent>
		<enclosure length="1897600" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.</itunes:subtitle><itunes:summary>Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Agentic AI, ChatGPT, CL-CRI-1131, CL-CRI-1163, Claude code, financial sector, NextChat, Shipping and Transportation, SOCKS5, SockTz</itunes:keywords></item>
		<item>
		<title>An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation</title>
		<link>https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/</link>
		
		<dc:creator><![CDATA[Renzon Cruz, Nicolas Bareil, Eric Semaan and Omar Jbari]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 10:00:46 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[Frontier AI]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186408</guid>

					<description><![CDATA[<p>Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/">An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>4</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/07_Opinion_Overview_1920x900-1-300x300.jpg</featuredImage>
		<dcterms:extent>4</dcterms:extent>
		<enclosure length="887924" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/07_Opinion_Overview_1920x900-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.</itunes:subtitle><itunes:summary>Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, Threat Research, Agentic AI, Frontier AI</itunes:keywords></item>
		<item>
		<title>Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams</title>
		<link>https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/</link>
		
		<dc:creator><![CDATA[Noam Sala]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 10:00:36 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Cloaked Ursa]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[Microsoft Teams]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[Remote Access Trojan]]></category>
		<category><![CDATA[Spoof]]></category>
		<category><![CDATA[Vishing]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186248</guid>

					<description><![CDATA[<p>Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/">Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>13</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-300x300.jpg</featuredImage>
		<dcterms:extent>13</dcterms:extent>
		<enclosure length="611028" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5.jpg"/>
			<itunes:explicit/><itunes:subtitle>Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.</itunes:subtitle><itunes:summary>Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Cloaked Ursa, Entra ID, Microsoft Teams, payload, PowerShell, Remote Access Trojan, Spoof, Vishing</itunes:keywords></item>
		<item>
		<title>Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety</title>
		<link>https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/</link>
		
		<dc:creator><![CDATA[Tony Li, Hongliang Liu and Yuhao Wu]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 22:00:07 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[LLM]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186235</guid>

					<description><![CDATA[<p>New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/">Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>4</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_General_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>4</dcterms:extent>
		<enclosure length="749555" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_General_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.</itunes:subtitle><itunes:summary>New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, AI, Jailbreak, LLM</itunes:keywords></item>
		<item>
		<title>The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution</title>
		<link>https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/</link>
		
		<dc:creator><![CDATA[Sara McBroom]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 10:00:57 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[DLL hijacking]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Sandbox]]></category>
		<category><![CDATA[VirusTotal]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=186148</guid>

					<description><![CDATA[<p>Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/">The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>7</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-300x300.png</featuredImage>
		<dcterms:extent>7</dcterms:extent>
		<enclosure length="2092628" type="image/png" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1.png"/>
			<itunes:explicit/><itunes:subtitle>Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.</itunes:subtitle><itunes:summary>Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, backdoor, Bitcoin, DLL hijacking, ransomware, Sandbox, VirusTotal</itunes:keywords></item>
	</channel>
</rss>