<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Unit 42</title>
	<atom:link href="https://unit42.paloaltonetworks.com/feed/?v=2" rel="self" type="application/rss+xml"/>
	<link>https://unit42.paloaltonetworks.com/</link>
	<description>Palo Alto Networks</description>
	<lastBuildDate>Fri, 22 May 2026 18:45:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-Unit42-180x180-1.png</url>
	<title>Unit 42</title>
	<link>https://unit42.paloaltonetworks.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<itunes:explicit>no</itunes:explicit><itunes:subtitle>Palo Alto Networks</itunes:subtitle><item>
		<title>Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns</title>
		<link>https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Fri, 22 May 2026 13:00:42 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Actor Groups]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[AppDomainManager]]></category>
		<category><![CDATA[DLL Sideloading]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[MiniJunk]]></category>
		<category><![CDATA[MiniUpdate]]></category>
		<category><![CDATA[operation security]]></category>
		<category><![CDATA[RATs]]></category>
		<category><![CDATA[screening serpens]]></category>
		<category><![CDATA[social engineering]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181080</guid>

					<description><![CDATA[<p>Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/">Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>20</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Boggy-Serpens-300x240.png</featuredImage>
		<dcterms:extent>20</dcterms:extent>
		<enclosure length="129994" type="image/png" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Boggy-Serpens.png"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Actor Groups, Advanced Persistent Threat, AppDomainManager, DLL Sideloading, Iran, MiniJunk, MiniUpdate, operation security, RATs, screening serpens, social engineering</itunes:keywords></item>
		<item>
		<title>Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</title>
		<link>https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/</link>
		
		<dc:creator><![CDATA[Bill Batchelor and Eyal Rafian]]></dc:creator>
		<pubDate>Fri, 22 May 2026 10:00:24 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Curious Serpens]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[Microsoft Azure]]></category>
		<category><![CDATA[Microsoft graph API]]></category>
		<category><![CDATA[Midnight Blizzard]]></category>
		<category><![CDATA[MITRE]]></category>
		<category><![CDATA[ROADtools]]></category>
		<category><![CDATA[UTA0355]]></category>
		<category><![CDATA[Void Blizzard]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=181397</guid>

					<description><![CDATA[<p>Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/">Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>14</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1-300x300.jpg</featuredImage>
		<dcterms:extent>14</dcterms:extent>
		<enclosure length="993522" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.</itunes:subtitle><itunes:summary>Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, Curious Serpens, Entra ID, Microsoft Azure, Microsoft graph API, Midnight Blizzard, MITRE, ROADtools, UTA0355, Void Blizzard</itunes:keywords></item>
		<item>
		<title>The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21)</title>
		<link>https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Thu, 21 May 2026 15:30:33 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Credential Harvesting]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[npm packages]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[worm propagation]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=179395</guid>

					<description><![CDATA[<p>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/">The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21)</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>22</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>22</dcterms:extent>
		<enclosure length="611893" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21) appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21) appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Malware, Credential Harvesting, GitHub, npm packages, obfuscation, payload, supply chain, worm propagation</itunes:keywords></item>
		<item>
		<title>Tracking TamperedChef Clusters via Certificate and Code Reuse</title>
		<link>https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/</link>
		
		<dc:creator><![CDATA[Joseph Ganter]]></dc:creator>
		<pubDate>Wed, 20 May 2026 10:00:46 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Appsuite PDF]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[CL-CRI-1089]]></category>
		<category><![CDATA[CL-UNK-1090]]></category>
		<category><![CDATA[DocuFlex]]></category>
		<category><![CDATA[EvilAI]]></category>
		<category><![CDATA[malvertising]]></category>
		<category><![CDATA[RATs]]></category>
		<category><![CDATA[Remote Access Trojan]]></category>
		<category><![CDATA[TamperedChef]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180970</guid>

					<description><![CDATA[<p>Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/">Tracking TamperedChef Clusters via Certificate and Code Reuse</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>21</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/07_Security-Technology_Category_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>21</dcterms:extent>
		<enclosure length="791236" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/07_Security-Technology_Category_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Adware, Appsuite PDF, certificates, CL-CRI-1089, CL-UNK-1090, DocuFlex, EvilAI, malvertising, RATs, Remote Access Trojan, TamperedChef</itunes:keywords></item>
		<item>
		<title>Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files</title>
		<link>https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/</link>
		
		<dc:creator><![CDATA[Pranay Kumar Chhaparwal and Mark Lim]]></dc:creator>
		<pubDate>Fri, 15 May 2026 10:00:52 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[Cryptocurrency]]></category>
		<category><![CDATA[gremlin stealer]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[Telegram]]></category>
		<category><![CDATA[VirusTotal]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180614</guid>

					<description><![CDATA[<p>Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/">Gremlin Stealer&#039;s Evolved Tactics: Hiding in Plain Sight With Resource Files</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>7</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/02_Malware_Category_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>7</dcterms:extent>
		<enclosure length="1869627" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/02_Malware_Category_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer&amp;#039;s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer&amp;#039;s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, API, Cryptocurrency, gremlin stealer, obfuscation, payload, Telegram, VirusTotal</itunes:keywords></item>
		<item>
		<title>Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools</title>
		<link>https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/</link>
		
		<dc:creator><![CDATA[Stav Setty, Tom Fakterman and Shachar Roitman]]></dc:creator>
		<pubDate>Mon, 11 May 2026 22:00:43 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AD CS attacks]]></category>
		<category><![CDATA[certificate template]]></category>
		<category><![CDATA[certipy]]></category>
		<category><![CDATA[ESC1]]></category>
		<category><![CDATA[Fighting Ursa]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[shadow credentials]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180347</guid>

					<description><![CDATA[<p>Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/">Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>14</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/04_Malware_Category_1920x900-2-300x300.jpg</featuredImage>
		<dcterms:extent>14</dcterms:extent>
		<enclosure length="1400619" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/04_Malware_Category_1920x900-2.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, Active Directory, AD CS attacks, certificate template, certipy, ESC1, Fighting Ursa, Microsoft, PKI, shadow credentials</itunes:keywords></item>
		<item>
		<title>Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution</title>
		<link>https://unit42.paloaltonetworks.com/captive-portal-zero-day/</link>
		
		<dc:creator><![CDATA[Justin Moore and Unit 42]]></dc:creator>
		<pubDate>Thu, 07 May 2026 00:00:53 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[CVE-2026-0300]]></category>
		<category><![CDATA[EarthWorm]]></category>
		<category><![CDATA[PAN-OS]]></category>
		<category><![CDATA[Remote Code Execution]]></category>
		<category><![CDATA[ReverseSocks5]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[zero-day]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180214</guid>

					<description><![CDATA[<p>Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/">Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>5</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-300x300.jpg</featuredImage>
		<dcterms:extent>5</dcterms:extent>
		<enclosure length="1645038" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Vulnerabilities, CVE-2026-0300, EarthWorm, PAN-OS, Remote Code Execution, ReverseSocks5, vulnerability, zero-day</itunes:keywords></item>
		<item>
		<title>Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years</title>
		<link>https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/</link>
		
		<dc:creator><![CDATA[Justin Moore]]></dc:creator>
		<pubDate>Tue, 05 May 2026 23:00:33 +0000</pubDate>
				<category><![CDATA[High Profile Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Containers]]></category>
		<category><![CDATA[CVE-2026-31431]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[local privilege escalation]]></category>
		<category><![CDATA[page cache]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180179</guid>

					<description><![CDATA[<p>Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/">Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>6</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-300x300.jpg</featuredImage>
		<dcterms:extent>6</dcterms:extent>
		<enclosure length="1480017" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42.</itunes:subtitle><itunes:summary>Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42.</itunes:summary><itunes:keywords>High Profile Threats, Vulnerabilities, Containers, CVE-2026-31431, Kubernetes, Linux, local privilege escalation, page cache, vulnerability</itunes:keywords></item>
		<item>
		<title>Essential Data Sources for Detection Beyond the Endpoint</title>
		<link>https://unit42.paloaltonetworks.com/detection-beyond-the-endpoint/</link>
		
		<dc:creator><![CDATA[Corey Berman and Matt Gayford]]></dc:creator>
		<pubDate>Fri, 01 May 2026 23:00:13 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=180120</guid>

					<description><![CDATA[<p>Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/detection-beyond-the-endpoint/">Essential Data Sources for Detection Beyond the Endpoint</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>4</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/13_Cloud_cybersecurity_research_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>4</dcterms:extent>
		<enclosure length="837387" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/13_Cloud_cybersecurity_research_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, Cloud Security, IAM, incident response, threat detection</itunes:keywords></item>
		<item>
		<title>That AI Extension Helping You Write Emails? It’s Reading Them First</title>
		<link>https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/</link>
		
		<dc:creator><![CDATA[Shresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher, Oleksii Starov, Qinge Xie and Fang Liu]]></dc:creator>
		<pubDate>Thu, 30 Apr 2026 22:00:57 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AI browser]]></category>
		<category><![CDATA[browser extension]]></category>
		<category><![CDATA[GenAI]]></category>
		<category><![CDATA[Infostealer]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Remote Access Trojan]]></category>
		<category><![CDATA[search hijacker]]></category>
		<category><![CDATA[spyware]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=179576</guid>

					<description><![CDATA[<p>Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/">That AI Extension Helping You Write Emails? It’s Reading Them First</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>13</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/AdobeStock_739390615-1-300x300.jpg</featuredImage>
		<dcterms:extent>13</dcterms:extent>
		<enclosure length="760563" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/AdobeStock_739390615-1.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, AI browser, browser extension, GenAI, Infostealer, malware, Remote Access Trojan, search hijacker, spyware</itunes:keywords></item>
		<item>
		<title>TGR-STA-1030: New Activity in Central and South America</title>
		<link>https://unit42.paloaltonetworks.com/new-activity-central-south-america/</link>
		
		<dc:creator><![CDATA[Unit 42]]></dc:creator>
		<pubDate>Fri, 24 Apr 2026 20:30:19 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[TGR-STA-1030]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=179467</guid>

					<description><![CDATA[<p>Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/new-activity-central-south-america/">TGR-STA-1030: New Activity in Central and South America</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>1</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/01_Nation-State-cyberattacks_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>1</dcterms:extent>
		<enclosure length="895709" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/01_Nation-State-cyberattacks_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. The post TGR-STA-1030: New Activity in Central and South America appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. The post TGR-STA-1030: New Activity in Central and South America appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, TGR-STA-1030</itunes:keywords></item>
		<item>
		<title>Frontier AI and the Future of Defense: Your Top Questions Answered</title>
		<link>https://unit42.paloaltonetworks.com/frontier-ai-top-questions-answered/</link>
		
		<dc:creator><![CDATA[Sam Rubin]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 20:45:50 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[GenAI]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[n-day]]></category>
		<category><![CDATA[open source]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=179376</guid>

					<description><![CDATA[<p>What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/frontier-ai-top-questions-answered/">Frontier AI and the Future of Defense: Your Top Questions Answered</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>4</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/03_Listicle_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>4</dcterms:extent>
		<enclosure length="1082016" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/03_Listicle_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking. The post Frontier AI and the Future of Defense: Your Top Questions Answered appeared first on Unit 42.</itunes:subtitle><itunes:summary>What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking. The post Frontier AI and the Future of Defense: Your Top Questions Answered appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, GenAI, LLM, n-day, open source</itunes:keywords></item>
		<item>
		<title>Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System</title>
		<link>https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/</link>
		
		<dc:creator><![CDATA[Yahav Festinger and Chen Doytshman]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 10:00:31 +0000</pubDate>
				<category><![CDATA[Cloud Cybersecurity Research]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[data exfiltration]]></category>
		<category><![CDATA[GCP]]></category>
		<category><![CDATA[Google Cloud]]></category>
		<category><![CDATA[LLMs]]></category>
		<category><![CDATA[multi-agent]]></category>
		<category><![CDATA[penetration testing]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=178504</guid>

					<description><![CDATA[<p>Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments. Learn critical insights and vital lessons for proactive security. </p>
<p>The post <a href="https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/">Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>12</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>12</dcterms:extent>
		<enclosure length="1163529" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments. Learn critical insights and vital lessons for proactive security. The post Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments. Learn critical insights and vital lessons for proactive security. The post Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System appeared first on Unit 42.</itunes:summary><itunes:keywords>Cloud Cybersecurity Research, Threat Research, AI, Cloud, data exfiltration, GCP, Google Cloud, LLMs, multi-agent, penetration testing</itunes:keywords></item>
		<item>
		<title>When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks</title>
		<link>https://unit42.paloaltonetworks.com/air-snitch-enterprise-wireless-attacks/</link>
		
		<dc:creator><![CDATA[Emmanuel Zhou, Adam Robbie, Rick Wyble, Zhutian Liu, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy and Mathy Vanhoef]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 10:00:22 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[AirSnitch]]></category>
		<category><![CDATA[MitM]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[port stealing]]></category>
		<category><![CDATA[WiFi encryption]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[WPA2]]></category>
		<category><![CDATA[WPA3]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=178804</guid>

					<description><![CDATA[<p>Unit 42 research reveals AirSnitch attacks bypass WPA2/3 Wi-Fi encryption and client isolation, exposing critical infrastructure vulnerabilities.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/air-snitch-enterprise-wireless-attacks/">When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>12</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/11_Security-Technology_Category_1505x922-300x300.jpg</featuredImage>
		<dcterms:extent>12</dcterms:extent>
		<enclosure length="1020703" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/11_Security-Technology_Category_1505x922.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 research reveals AirSnitch attacks bypass WPA2/3 Wi-Fi encryption and client isolation, exposing critical infrastructure vulnerabilities. The post When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 research reveals AirSnitch attacks bypass WPA2/3 Wi-Fi encryption and client isolation, exposing critical infrastructure vulnerabilities. The post When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks appeared first on Unit 42.</itunes:summary><itunes:keywords>Malware, Threat Research, AirSnitch, MitM, network security, port stealing, WiFi encryption, wireless, WPA2, WPA3</itunes:keywords></item>
		<item>
		<title>Fracturing Software Security With Frontier AI Models</title>
		<link>https://unit42.paloaltonetworks.com/ai-software-security-risks/</link>
		
		<dc:creator><![CDATA[Andy Piazza]]></dc:creator>
		<pubDate>Mon, 20 Apr 2026 10:00:14 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[attack path]]></category>
		<category><![CDATA[data exfiltration]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[n-day]]></category>
		<category><![CDATA[Open Source Software]]></category>
		<category><![CDATA[zero-day]]></category>
		<guid isPermaLink="false">https://unit42.paloaltonetworks.com/?p=177819</guid>

					<description><![CDATA[<p>Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/ai-software-security-risks/">Fracturing Software Security With Frontier AI Models</a> appeared first on <a href="https://unit42.paloaltonetworks.com">Unit 42</a>.</p>
]]></description>
		
		
		
		<readTime>6</readTime>
		<featuredImage>https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/06_General_Overview_1920x900-300x300.jpg</featuredImage>
		<dcterms:extent>6</dcterms:extent>
		<enclosure length="959184" type="image/jpeg" url="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/06_General_Overview_1920x900.jpg"/>
			<itunes:explicit/><itunes:subtitle>Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42.</itunes:subtitle><itunes:summary>Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42.</itunes:summary><itunes:keywords>General, Insights, AI, attack path, data exfiltration, malware, n-day, Open Source Software, zero-day</itunes:keywords></item>
	</channel>
</rss>