September 16, 2026
- NeuralOverride puts an LLM into a RAT’s planning loop, but its ICS capability appears incomplete. Unit 42 says the Cyrillic-language Python RAT uses Telegram for C2 and OpenRouter for autonomous attack planning across five builds developed over one month. Its SCADA tasking references a missing
scada_commander.py, indicating stubs rather than a working OT module (Unit 42).
· AI & Agent Security - ZionSiphon v4 rewrites an OT sabotage tool in Rust. Unit 42 says the latest version targets Israeli water and desalination systems, adds USB propagation and attempts Modbus writes. The post does not report successful physical disruption (Unit 42).
· Threat Activity & Malware
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
September 5, 2026
- VoidShadow: Unit 42 details a modular Linux+Windows implant for full remote control and credential theft that shapes its C2 to look like Microsoft Graph, WordPress, and Google Cloud traffic, with userland and kernel rootkits for concealment (Unit 42).
· Threat Activity & Malware
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
September 3, 2026
- Autonomous agents did the intrusion work in a real ransomware case. Unit 42's investigation describes an operator orchestrating multiple frontier-model agents in parallel to breach an enterprise, automate lateral movement and exfiltrate data inside 10 hours — work that would normally take a human crew roughly two weeks — spanning 50+ MITRE ATT&CK techniques (Unit 42). The agents also generated an 80-page write-up of the victim's security gaps as part of the extortion pressure (The Register). Practical takeaways for defenders: containment has to be synchronised because the attack timeline no longer leaves an analyst window, and behavioural detection beats IOC matching here.
· AI-Enabled Attacks & Agent Security
- Spring Ring's Teams vishing ends in NTLM relay against domain controllers. Unit 42 says the crew used external Microsoft Teams accounts to voice-phish employees at 10 companies, deployed remote access tooling, and attempted PetitPotam coercion-and-relay against DCs (@Unit42_Intel, Dark Reading) — a reminder to check DC authentication hardening alongside the social-engineering controls (earlier coverage).
· Threat Activity
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
September 1, 2026
- Unit 42 analysed 405 "AI malware" samples and found 97% exist only in sandboxes and research repos, with existing endpoint analytics and behavioural controls stopping every production sample: AI changes how code is authored, not how it executes (Unit 42). Worth pairing with @Blackicelabs's caveat that "never left the sandbox" and "nobody hunted outside it" produce identical telemetry.
· AI & Model Security
- Spring Ring runs voice phishing inside Microsoft Teams, impersonating IT staff to coerce users into deploying malware or handing over domain access; Unit 42 says detection rests on behavioural anomalies rather than content filtering (Unit 42).
· Threat Activity
in Attackers Are Living in the Management Plane
August 26, 2026
- Kimwolf v7 makes Android TV-box DDoS traffic look more like legitimate browser requests. The bot adds HTTP/2 flooding and browser-fingerprint spoofing, complicating traffic-based filtering, according to Unit 42.
· Threat Activity & Supply Chain
in Oracle WebLogic Is Under Active Attack
August 25, 2026
- Identity phishing is moving into internal collaboration channels. Unit 42 describes attackers sending direct messages inside trusted chat platforms that link to reverse-proxy infrastructure, harvesting credentials and MFA tokens in real time — the AiTM playbook, minus the email gateway (@Unit42_Intel).
· Offensive Tradecraft & Detection
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 20, 2026
- The Aeternum botnet stores C2 instructions in Polygon smart contracts, retrieving immutable commands via public RPC endpoints to resist takedown (Unit 42).
· Threat Intelligence
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 17, 2026
- theHatman selling ~3.6M Azure/Entra records from Fortune 500 tenants. The actor claims to have exfiltrated employee and identity databases after gaining access via compromised credentials; Unit 42 hasn't verified the intrusion vector but recommends credential-attack mitigations, warning of downstream social engineering (BleepingComputer, SecurityWeek).
· Cloud & Identity
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 12, 2026
- Unit 42 analyzed Aeternum, a blockchain-enabled Windows botnet loader that anchors decentralized C2 in Polygon smart contracts, with multi-stage payloads, Telegram-based encrypted exfiltration, and anti-analysis for crypto-mining and remote access (Unit 42).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
August 5, 2026
- Malware can hijack passkey-protected accounts without a PIN. Unit 42 detailed three attack paths — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — against Chrome's Google Password Manager cloud authenticator, letting ordinary-user malware on Windows sign into passkey-protected accounts with no fingerprint, PIN, or on-screen prompt; the strongest variant targets the master key (The Hacker News).
· Vulnerabilities & Exploits
in Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing
August 4, 2026
- Two new passkey attack classes surfaced. "Pass-ta-key" shows malware can hijack Google-synced passkeys through password-manager weaknesses to seize passkey-protected accounts (BleepingComputer). Separately, Unit 42 documents relying parties that fail to validate the User Verified flag, quietly downgrading passkey MFA to a single factor (Unit 42) (discussion).
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
August 1, 2026
- A Chinese-speaking threat actor is running autonomous attacks by wiring the DeepSeek model into the open-source Hermes Agent framework. Palo Alto Unit 42 reports that after a single Telegram instruction, the agent independently discovered internet-facing systems, selected public exploits, and ran the session with no further operator input; the operator is tracked under the aliases knaithe and KnYuan (BleepingComputer, The Hacker News). This is a concrete continuation of the Hermes-driven activity seen against Thailand's finance ministry.
· AI & Offensive Security
- Unit 42 flagged a fresh wave of malicious npm and PyPI packages, 65% previously unknown, spanning
.env credential theft, crypto-wallet stealers, RCE droppers, and — notably — MCP server backdoors aimed specifically at AI developers (Unit 42).
· Supply Chain
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 31, 2026
- Unit 42 analyzed an AI-enabled campaign by a Chinese-speaking threat actor that combined autonomous AI-driven enumeration across seven vulnerabilities with manual exploitation — a concrete field sighting of agentic tooling folded into a live intrusion set (Unit 42).
· AI & Model Security
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
July 30, 2026
- 15+ Chrome productivity extensions bundle an undisclosed SDK that turns the browser into a covert web-crawling proxy, per Unit 42 — no mention of crawling in the store listing, only a post-install opt-in popup. Unit 42
· Threat Intelligence & Research
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 26, 2026
- Russia's Laundry Bear (Void Blizzard / TA488) campaign against Zimbra got a technical anatomy from Unit 42, tracking it as CL-STA-1114: the zero-click XSS payload (CVE-2025-66376) grabs the last 90 days of mail, the org's full email directory, browser-saved passwords, and 2FA recovery codes the moment a message loads, per The Hacker News and BleepingComputer (earlier coverage).
· Threat Activity
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 25, 2026
- Device-code phishing gets stealthier. Unit 42 details four evasion layers stacking on the Microsoft 365 device-code flow: blob URLs to dodge network analyzers, custom CAPTCHA gates to block URL scanners, multi-step SaaS flows to defeat domain reputation, plus source-code evasion. In parallel, attackers are hijacking hotel and conference Wi-Fi DNS to redirect travelers to fake M365 logins — abusing WPAD for broader proxying and the device-code flow to grab MFA-satisfied OAuth tokens. Unit 42, BleepingComputer.
· Cloud & Identity
- Rhadamanthys impersonates RingCentral after a takedown. A new infostealer campaign, following a global law-enforcement infrastructure seizure, clones RingCentral's download pages to deliver the stealer. Unit 42.
· Threat Activity
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public
July 23, 2026
- "FALCON" extortion group profiled — Unit 42 (tracking as CL-CRI-1182) documented a vishing playbook and passkey-themed phishing domains, assessed with moderate confidence as related to BlackFile (Unit 42).
· Threat Activity
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- Attackers used AI to bulk-generate 350+ new fake VPN browser extensions across 47 accounts since Unit 42's first report, backed by 30 proxy backend domains on
.space and .online TLDs and 3,000+ installs. Unit 42.
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 19, 2026
- Siemens ROX II OT switches hit by a three-bug zero-day chain. Unit 42 detailed a trilogy of flaws that chain from initial access to privilege escalation and persistent root on the industrial switches; Siemens is pushing firmware updates and mitigations (Unit 42).
· Vulnerabilities & Exploits
- Unit 42 flags an Equation Group-style implant in the wild, initially resembling a known NSA TAO sample by reusing an exported function name — worth watching as analysis develops (via @0xpwnie).
· Threat Activity
- npm supply-chain attackers exploited a gap in the CI/CD pipeline itself, with Unit 42 also observing an attacker leveraging GitHub Copilot to trigger infection (Unit 42).
· Cloud, Identity & Supply Chain
in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation
July 18, 2026
- New ClickFix variant uses on-the-fly WebAssembly and SVG steganography to serve fake verification pages (Unit 42); relatedly, ACR Stealer rides ClickFix "paste-into-Run" lures to steal browser tokens and Microsoft 365 / OneDrive / SharePoint files (The Hacker News).
· Threat Activity
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 16, 2026
- Unit 42 analyzed TuxBot v3 "Evolution," a modular IoT botnet framework showing signs of LLM-assisted development — functional DDoS core, but several exploit and fallback features broken by development bugs. Unit 42, The Hacker News
· AI & Model Security
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
July 10, 2026
- Factory-v3, tracked by Unit 42, is a financially-motivated framework pairing unique per-build Go binaries with DLL search-order hijacking to bypass security filters, distributing both the Vidar stealer and the XMRig miner. Unit 42 (X)
· Malware & Endpoint Evasion
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
July 7, 2026
- Unit 42 notes LLMs consistently hallucinate fictitious domains for legitimate brands; attackers are registering these to intercept traffic from automated AI systems and developers, and one actor was seen building a phishing kit around such a domain (Unit 42).
· AI & Model Security
in A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary
July 4, 2026
- AppDomainManager injection delivers a new .NET backdoor. Unit 42 tracked a campaign against energy and government entities in Southeast Asia that used AppDomainManager injection to load TinyRCT, a previously undocumented .NET backdoor. Unit 42
· Offensive & Red Team
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
June 21, 2026
- Unit 42 disclosed a cross-tenant RCE in the Google Cloud Vertex AI SDK for Python ("Pickle in the Middle"): predictable staging-bucket names let an attacker with no project access squat the bucket and hijack a victim's model upload, achieving code execution inside Google's serving infrastructure via pickle deserialization. Fixed in
google-cloud-aiplatform v1.148.0 (Unit 42, The Hacker News).
· AI & Model Security - Microsoft detailed AutoJack, an exploit chain that turns an AI browsing agent into an RCE delivery vehicle: steer the agent to an attacker page, and its JavaScript reaches a privileged local service to spawn a host process — no credentials or further interaction required (The Hacker News). Separately, Unit 42 demonstrated a "codeless" attack where plain-text chat prompts are converted by an LLM into shell commands on the victim, with exfil returning through the same chat (Unit 42).
· AI & Model Security
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- Unit 42's "Pickle in the Middle" abused predictable staging-bucket names in the Google Vertex AI SDK (
google-cloud-aiplatform 1.139.0–1.140.0) to hijack victim model uploads via bucket squatting and pickle deserialization, achieving cross-tenant RCE inside Google's serving infrastructure. Fixed in v1.148.0. Unit 42, The Hacker News
· AI & Model Security
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token