Visualização normal

Antes de ontemStream principal

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

2 de Setembro de 2026, 07:00

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.

The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

28 de Agosto de 2026, 19:00

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.

The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

21 de Agosto de 2026, 20:00

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls

The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

Por:Xu Zou
4 de Agosto de 2026, 10:00

Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.

The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42.

How We Added WebAuthn to a Browser-Based RDP Client

2 de Julho de 2026, 19:00

A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection.

The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.

  • ✇Firewall Daily – The Cyber Express
  • Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA Samiksha Jain
    Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States. Accordin
     

Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA

Seized Crypto Assets

Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.

According to Ukrainian authorities, the transferred cryptocurrency is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.

Seized Crypto Assets Moved to ARMA After Court Order

The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.

Investigators determined that the virtual assets were stored in crypto wallets controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.

Authorities said this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.

Investigation Links Cryptocurrency to International Hacking Group

According to investigators, members of the international hacking group carried out large-scale cyberattacks against individuals and companies in Europe and the United States.

The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.

Authorities estimate that the criminal group's activities caused losses exceeding $100 million.

As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.

More Than $11 Million in Assets Seized

The investigation resulted in the cryptocurrency seizure and the confiscation of additional assets with a combined value exceeding $11.1 million.

According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets equivalent to more than $8.3 million.

The Office of the Prosecutor General is providing procedural oversight for the criminal proceedings.

Authorities Plan to Convert Crypto Into Military Bonds

The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.

According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.

Officials described countering transnational cybercrime and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.

ARMA Expands Digital Asset Management

ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.

The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.

ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.

The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

18 de Agosto de 2026, 16:05

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks.

The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.

Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered

12 de Junho de 2026, 19:00

Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here.

The post Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered appeared first on Unit 42.

When “Hi, This Is IT” Comes Through Microsoft Teams

8 de Junho de 2026, 20:00

Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security.

The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42.

2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

28 de Maio de 2026, 07:00

The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here.

The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42.

Out of the Crypt: The Evolving Cyber Extortion Economy

27 de Maio de 2026, 19:00

Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance.

The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42.

  • ✇Firewall Daily – The Cyber Express
  • 7-Eleven Confirms Hack After Appearing on ShinyHunters Leak List Samiksha Jain
    7-Eleven has confirmed that its internal systems were breached in April 2026, exposing personal information linked to franchisee application records. The disclosure of 7-Eleven data breach comes weeks after the ShinyHunters ransomware group listed the retailer as part of its latest “pay-or-leak” extortion campaign. The company has started notifying affected individuals through a formal “Notice of Security Incident,” according to a filing submitted to the Maine Attorney General’s Office on May
     

7-Eleven Confirms Hack After Appearing on ShinyHunters Leak List

7-Eleven data breach

7-Eleven has confirmed that its internal systems were breached in April 2026, exposing personal information linked to franchisee application records. The disclosure of 7-Eleven data breach comes weeks after the ShinyHunters ransomware group listed the retailer as part of its latest “pay-or-leak” extortion campaign. The company has started notifying affected individuals through a formal “Notice of Security Incident,” according to a filing submitted to the Maine Attorney General’s Office on May 15. In the notification letter, 7-Eleven stated that it discovered the breach on April 8, 2026, after an unauthorized third party gained access to systems used to store franchisee documents. The company said the affected records contained information submitted during franchise applications, including names, addresses, and additional undisclosed data elements. However, 7-Eleven has not confirmed the total number of individuals impacted by the incident. The 7-Eleven data breach has raised concerns due to the retailer’s massive franchise network across North America. According to the company, nearly 75% of its US stores operate under franchise ownership.

Investigation Underway Into 7-Eleven Data Breach

In its notice to affected individuals, 7-Eleven said it immediately launched an investigation with the support of a forensic security firm to assess the scope of the breach and secure compromised systems. The company stated that it has since remediated the incident and is offering affected individuals 24 months of complimentary identity theft protection and CyberScan credit monitoring services through IDX. The notification also advised recipients to monitor bank accounts, review credit reports, and consider placing fraud alerts or credit freezes with consumer reporting agencies including Equifax, Experian, and TransUnion. 7-Eleven’s Chief Information Security Officer, Jim Kastle, signed the notification letter sent to impacted individuals. The company apologized for the incident and said it was taking steps to strengthen its security measures.

ShinyHunters Connection Draws Attention

The disclosure follows recent claims made by the ShinyHunters cybercrime group, which allegedly added 7-Eleven to its list of victims in a broader cyber extortion campaign. While 7-Eleven has not officially attributed the breach to ShinyHunters or confirmed whether ransomware was involved, the timing of the disclosure has fueled speculation about a possible connection. The ShinyHunters group has previously been linked to multiple high-profile data breaches and extortion operations targeting global organizations. The group is known for stealing sensitive corporate data and pressuring victims into paying ransom demands to prevent public leaks. Cybersecurity experts note that franchise-related systems are increasingly becoming attractive targets for cybercriminals because they often contain personally identifiable information, financial records, and operational data tied to thousands of independent operators.

Franchise Network Could Increase Impact

7-Eleven operates nearly 13,000 stores across North America and more than 85,000 locations globally as of April 2026. The company is currently owned by Tokyo-based Seven & i Holdings, which also owns Speedway and Stripes convenience store brands. Given the scale of the retailer’s franchise operations, the full impact of the 7-Eleven data breach remains unclear. The company has not disclosed whether financial details, Social Security numbers, or other sensitive records were accessed during the intrusion. The Cyber Express reached out to 7-Eleven for additional clarification regarding the number of affected individuals and the nature of the compromised data but had not received a response at the time of publication.

Essential Data Sources for Detection Beyond the Endpoint

1 de Maio de 2026, 20:00

Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here.

The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42.

Frontier AI and the Future of Defense: Your Top Questions Answered

23 de Abril de 2026, 17:45

What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking.

The post Frontier AI and the Future of Defense: Your Top Questions Answered appeared first on Unit 42.

  • ✇Unit 42
  • Fracturing Software Security With Frontier AI Models Andy Piazza
    Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42.
     

Fracturing Software Security With Frontier AI Models

20 de Abril de 2026, 07:00

Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching.

The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42.

❌
❌