Visualização normal

Hoje — 9 de Setembro de 2026Stream principal

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

9 de Setembro de 2026, 07:00

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks.

The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

Antes de ontemStream principal

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

2 de Setembro de 2026, 07:00

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.

The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

31 de Agosto de 2026, 07:00

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

25 de Agosto de 2026, 07:00

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.

The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Identity Abuse Through Trusted Communication Channels

20 de Agosto de 2026, 07:00

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.

The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

Kimwolf v7: An Evolution of the Kimwolf Botnet

11 de Agosto de 2026, 07:00

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.

The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

10 de Agosto de 2026, 19:00

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.

The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

6 de Agosto de 2026, 07:00

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.

The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.

Almost Half of Malware Samples Communicate Direct to IP

4 de Agosto de 2026, 09:50

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.

The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

3 de Agosto de 2026, 07:00

Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.

The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

31 de Julho de 2026, 07:00

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.

The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

30 de Julho de 2026, 07:00

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.

The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

  • ✇Unit 42
  • Russian Global Webmail Espionage Unit 42
    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
     

Russian Global Webmail Espionage

23 de Julho de 2026, 11:10

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials.

The post Russian Global Webmail Espionage appeared first on Unit 42.

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

17 de Julho de 2026, 07:00

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.

The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

15 de Julho de 2026, 07:00

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.

The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination.

The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.

How We Added WebAuthn to a Browser-Based RDP Client

2 de Julho de 2026, 19:00

A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection.

The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

25 de Junho de 2026, 19:00

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.

The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.

❌
❌