<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Unit 42</title>
	<atom:link href="https://unit42.paloaltonetworks.com/feed/?v=2" rel="self" type="application/rss+xml"/>
	<link>https://unit42.paloaltonetworks.com/</link>
	<description>Palo Alto Networks</description>
	<lastBuildDate>Wed, 29 Jul 2026 20:45:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-Unit42-180x180-1.png</url>
	<title>Unit 42</title>
	<link>https://unit42.paloaltonetworks.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<itunes:explicit>no</itunes:explicit><itunes:subtitle>Palo Alto Networks</itunes:subtitle><item>
		<title>Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks</title>
		<link>https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/</link>
		
		<dc:creator><![CDATA[Andy Piazza]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 10:00:52 +0000</pubDate>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[Claude code]]></category>
		<category><![CDATA[CVEs]]></category>
		<category><![CDATA[DeepSeek]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[Hermes Agent]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=184241</guid>

					<description><![CDATA[<p>Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/">Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>10</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-300x300.jpeg</featuredImage>
		<dcterms:extent>10</dcterms:extent>
		<enclosure length="228623" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-scaled.jpeg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.</itunes:summary><itunes:keywords>Threat Research, Vulnerabilities, ChatGPT, Claude code, CVEs, DeepSeek, exploitation, Hermes Agent</itunes:keywords></item>
		<item>
		<title>Russian Global Webmail Espionage</title>
		<link>https://unit42.paloaltonetworks.com/russian-webmail-espionage/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 14:10:53 +0000</pubDate>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[CL-STA-1114]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[javascript injection]]></category>
		<category><![CDATA[Nation-state]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Zimbra webmail]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=184075</guid>

					<description><![CDATA[<p>Unit 42 details a Russian cyberespionage campaign targeting  Zimbra webmail servers using JavaScript injection to steal credentials.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">Russian Global Webmail Espionage</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>3</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-300x300.jpg</featuredImage>
		<dcterms:extent>3</dcterms:extent>
		<enclosure length="1508396" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.</itunes:summary><itunes:keywords>Cybercrime, Threat Research, CL-STA-1114, JavaScript, javascript injection, Nation-state, obfuscation, phishing, Zimbra webmail</itunes:keywords></item>
		<item>
		<title>Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy</title>
		<link>https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira]]></dc:creator>
		<pubDate>Fri, 17 Jul 2026 10:00:24 +0000</pubDate>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Command injection]]></category>
		<category><![CDATA[CVE-2025-40947]]></category>
		<category><![CDATA[CVE-2025-40948]]></category>
		<category><![CDATA[CVE-2025-40949]]></category>
		<category><![CDATA[Exploit Chain]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[Rox II OT switches]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183790</guid>

					<description><![CDATA[<p>A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/">Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>9</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>9</dcterms:extent>
		<enclosure length="1556434" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.</itunes:subtitle><itunes:summary>A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.</itunes:summary><itunes:keywords>Threat Research, Vulnerabilities, Command injection, CVE-2025-40947, CVE-2025-40948, CVE-2025-40949, Exploit Chain, privilege escalation, Rox II OT switches</itunes:keywords></item>
		<item>
		<title>AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report</title>
		<link>https://unit42.paloaltonetworks.com/ai-insights-incident-response-report/</link>
		
		<dc:creator><![CDATA[Ria Bhatia]]></dc:creator>
		<pubDate>Thu, 16 Jul 2026 23:00:59 +0000</pubDate>
				<category><![CDATA[Insights]]></category>
		<category><![CDATA[Opinions]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Unit 42 Incident Response Report]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183816</guid>

					<description><![CDATA[<p>Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ai-insights-incident-response-report/">AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>5</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Opinion_Category_1505x922-1-300x300.jpg</featuredImage>
		<dcterms:extent>5</dcterms:extent>
		<enclosure length="461728" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Opinion_Category_1505x922-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.</itunes:subtitle><itunes:summary>Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.</itunes:summary><itunes:keywords>Insights, Opinions, AI, LLM, Unit 42 Incident Response Report</itunes:keywords></item>
		<item>
		<title>The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)</title>
		<link>https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 23:00:33 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Credential Harvesting]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[npm packages]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[worm propagation]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=179395</guid>

					<description><![CDATA[<p>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/">The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>27</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>27</dcterms:extent>
		<enclosure length="611893" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Malware, Credential Harvesting, GitHub, npm packages, obfuscation, payload, supply chain, worm propagation</itunes:keywords></item>
		<item>
		<title>TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development</title>
		<link>https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/</link>
		
		<dc:creator><![CDATA[Chris Navarrete, Asher Davila and Doel Santos]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 10:00:54 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[C2]]></category>
		<category><![CDATA[DGA]]></category>
		<category><![CDATA[docker compose]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[TuxBot v3 Evolution]]></category>
		<category><![CDATA[VirusTotal]]></category>
		<category><![CDATA[XOR]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183516</guid>

					<description><![CDATA[<p>TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/">TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>23</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-1-300x300.jpeg</featuredImage>
		<dcterms:extent>23</dcterms:extent>
		<enclosure length="228623" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-1-scaled.jpeg"/>
			<itunes:explicit/><itunes:subtitle>TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.</itunes:subtitle><itunes:summary>TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, C2, DGA, docker compose, malware, TuxBot v3 Evolution, VirusTotal, XOR</itunes:keywords></item>
		<item>
		<title>No Manners Here: The Ruthless Rise of The Gentlemen Ransomware</title>
		<link>https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/</link>
		
		<dc:creator><![CDATA[Matt Brady]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 22:00:39 +0000</pubDate>
				<category><![CDATA[Hospitality Hacks and Retail Reality Checks]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Howling Scorpius]]></category>
		<category><![CDATA[RaaS]]></category>
		<category><![CDATA[Spikey Scorpius]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183458</guid>

					<description><![CDATA[<p>Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/">No Manners Here: The Ruthless Rise of The Gentlemen Ransomware</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>5</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/05_Opinion_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>5</dcterms:extent>
		<enclosure length="605305" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/05_Opinion_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.</itunes:summary><itunes:keywords>Hospitality Hacks and Retail Reality Checks, Insights, Howling Scorpius, RaaS, Spikey Scorpius</itunes:keywords></item>
		<item>
		<title>Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation</title>
		<link>https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/</link>
		
		<dc:creator><![CDATA[Bharath Nannaka and Pranay Kumar Chhaparwal]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 22:00:21 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AMSI]]></category>
		<category><![CDATA[Cryptocurrency]]></category>
		<category><![CDATA[DLL Sideloading]]></category>
		<category><![CDATA[Factory-v3]]></category>
		<category><![CDATA[malvertising]]></category>
		<category><![CDATA[X3D MINER]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183287</guid>

					<description><![CDATA[<p>A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/">Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>10</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/01_Malware_Category_1920x900-2-300x300.jpg</featuredImage>
		<dcterms:extent>10</dcterms:extent>
		<enclosure length="611028" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/01_Malware_Category_1920x900-2.jpg"/>
			<itunes:explicit/><itunes:subtitle>A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.</itunes:subtitle><itunes:summary>A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, AMSI, Cryptocurrency, DLL Sideloading, Factory-v3, malvertising, X3D MINER</itunes:keywords></item>
		<item>
		<title>How We Added WebAuthn to a Browser-Based RDP Client</title>
		<link>https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/</link>
		
		<dc:creator><![CDATA[Daniel Prizmant]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 22:00:39 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[IDA Pro]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[RDP]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183236</guid>

					<description><![CDATA[<p>A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/">How We Added WebAuthn to a Browser-Based RDP Client</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>8</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Myth-Busting_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>8</dcterms:extent>
		<enclosure length="938745" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Myth-Busting_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.</itunes:subtitle><itunes:summary>A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, Threat Research, IDA Pro, Microsoft, RDP</itunes:keywords></item>
		<item>
		<title>Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector</title>
		<link>https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/</link>
		
		<dc:creator><![CDATA[Keerthiraj Nagaraj, Diva-Oriane Marty, Beliz Kaleli and Oleksii Starov]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 01:00:11 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[LLMs]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[malvertising]]></category>
		<category><![CDATA[Phantom Squatting]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[slopsquatting]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[URL hallucination]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=183096</guid>

					<description><![CDATA[<p>Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/">Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>19</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_799983387-1-1-300x300.jpg</featuredImage>
		<dcterms:extent>19</dcterms:extent>
		<enclosure length="503127" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_799983387-1-1-scaled.jpg"/>
			<itunes:explicit/><itunes:subtitle>Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.</itunes:subtitle><itunes:summary>Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Agentic AI, LLMs, Malicious Domains, malvertising, Phantom Squatting, phishing, slopsquatting, supply chain, URL hallucination</itunes:keywords></item>
		<item>
		<title>Threat Brief: Mitigating Large-Scale Credential Attacks</title>
		<link>https://unit42.paloaltonetworks.com/large-scale-credential-attacks/</link>
		
		<dc:creator><![CDATA[Andy Piazza]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 19:05:33 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[credential theft]]></category>
		<category><![CDATA[fortibleed]]></category>
		<category><![CDATA[password spraying]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182713</guid>

					<description><![CDATA[<p>We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/large-scale-credential-attacks/">Threat Brief: Mitigating Large-Scale Credential Attacks</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>5</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-1-300x300.jpg</featuredImage>
		<dcterms:extent>5</dcterms:extent>
		<enclosure length="1486607" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42.</itunes:subtitle><itunes:summary>We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42.</itunes:summary><itunes:keywords>General, High Profile Threats, credential theft, fortibleed, password spraying</itunes:keywords></item>
		<item>
		<title>CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure</title>
		<link>https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 22:00:52 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[CL-STA-1062]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mimikatz]]></category>
		<category><![CDATA[southeast asia]]></category>
		<category><![CDATA[TinyRCT]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[web shells]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182868</guid>

					<description><![CDATA[<p>Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/">CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>10</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/03_Malware_Category_1920x900-5-300x300.jpg</featuredImage>
		<dcterms:extent>10</dcterms:extent>
		<enclosure length="874605" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/03_Malware_Category_1920x900-5.jpg"/>
			<itunes:explicit/><itunes:subtitle>Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.</itunes:subtitle><itunes:summary>Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, backdoor, CL-STA-1062, malware, Mimikatz, southeast asia, TinyRCT, VPN, web shells</itunes:keywords></item>
		<item>
		<title>OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat</title>
		<link>https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/</link>
		
		<dc:creator><![CDATA[Shresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher and Oleksii Starov]]></dc:creator>
		<pubDate>Tue, 23 Jun 2026 22:00:51 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[ClawHavoc]]></category>
		<category><![CDATA[ClawHub]]></category>
		<category><![CDATA[defense evasion]]></category>
		<category><![CDATA[Infostealer]]></category>
		<category><![CDATA[OpenClaw]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[VirusTotal]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182742</guid>

					<description><![CDATA[<p>Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/">OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>9</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_768915868-1-300x300.jpg</featuredImage>
		<dcterms:extent>9</dcterms:extent>
		<enclosure length="2020533" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_768915868-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Agentic AI, ClawHavoc, ClawHub, defense evasion, Infostealer, OpenClaw, payload, VirusTotal</itunes:keywords></item>
		<item>
		<title>The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration</title>
		<link>https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/</link>
		
		<dc:creator><![CDATA[Yahav Festinger]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 22:00:04 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[bucket hijacking]]></category>
		<category><![CDATA[cloud data exfiltration]]></category>
		<category><![CDATA[cloud logging]]></category>
		<category><![CDATA[CSPs]]></category>
		<category><![CDATA[Google Cloud]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Microsoft Azure]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182610</guid>

					<description><![CDATA[<p>Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/">The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>13</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/09_Cloud_cybersecurity_research_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>13</dcterms:extent>
		<enclosure length="1265691" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/09_Cloud_cybersecurity_research_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, AWS, bucket hijacking, cloud data exfiltration, cloud logging, CSPs, Google Cloud, IAM, Microsoft Azure, privilege escalation</itunes:keywords></item>
		<item>
		<title>Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE</title>
		<link>https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/</link>
		
		<dc:creator><![CDATA[Ori Hadad]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 10:00:29 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[bucket squatting]]></category>
		<category><![CDATA[Google Cloud]]></category>
		<category><![CDATA[joblib]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[RCE]]></category>
		<category><![CDATA[SDKs]]></category>
		<category><![CDATA[Vertex AI]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=182510</guid>

					<description><![CDATA[<p>Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/">Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>12</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_1270203474-1-300x300.png</featuredImage>
		<dcterms:extent>12</dcterms:extent>
		<enclosure length="2082712" type="image/png" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_1270203474-1.png"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, bucket squatting, Google Cloud, joblib, Python, RCE, SDKs, Vertex AI, vulnerability</itunes:keywords></item>
	</channel>
</rss>