Tag

#Unit 42

14 stories taggedUnit 42.

Illustration: a physical combination lock left open
AI Security

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed

Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

5 min read
Illustration: A vast server room at night, rows of black server racks with cold blue and amber indicator lights casting
AI Security

Who Is Running Up Your AI Bill at 3am

Security researchers have mapped an ecosystem of more than 80,000 proxy servers quietly routing stolen AI credentials to frontier models, and companies are footing bills they never ran up.

5 min read
Illustration: a glowing laptop keyboard at night with a faint holographic key hovering above the enter key
Identity & Access

Attackers Are Logging In, Not Breaking In

AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

4 min read
A cybersecurity operations center with multiple monitors showing successful threat detection and blocked breach attempts, representing defended systems
Threat Intelligence

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.

A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

3 min read
A corporate network map with AI-driven attack pathways spreading rapidly through nodes in real-time, system compromises represented as cascading failures compre
Ransomware

AI-Assisted Ransomware Gang Tore Through a Corporate Network in Under 10 Hours

Unit 42 researchers watched attackers use AI agents to do in a single working day what normally takes criminal crews two weeks. The case is a signal, not an outlier.

4 min read
A research lab workspace with malware analysis software displayed across multiple monitors, showing binary code and detection signatures, with a small portion o
Threat Intelligence

AI Malware Is Real. It Is Also Mostly Hype.

Palo Alto Networks studied 405 malware samples linked to AI tools. Only 12 ever reached a real computer, and existing defences caught every single one.

4 min read
Network traffic visualization showing data streams disguised as normal HTTP/2 sessions, with hidden malicious packets highlighted within legitimate-looking web
Threat Intelligence

New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic

Palo Alto Networks says the upgraded Android and smart-device botnet hides its floods inside HTTP/2 sessions that look like ordinary browsing.

3 min read
Security researcher at workstation displaying Chrome browser and password manager interface, malware attack path diagrams and vulnerability demonstrations on mu
Identity & Access

Malware Can Silently Hijack Chrome Passkeys, Researchers Show

Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

3 min read
A smartphone screen displaying a Telegram chat interface with an AI agent executing commands autonomously, system notifications showing target selection and exp
AI Security

Chinese Operator Turns DeepSeek Into a Self-Driving Hacker via Telegram

Unit 42 says an attacker gave one Telegram command and let an AI agent pick the targets, choose the exploits, and run the intrusion on its own.

3 min read
Illustration: A cluttered small-business office desk at night
Threat Intelligence

Fake Pirated Software Ads Are Draining Passwords and Hijacking Computers to Mine Crypto

A campaign uncovered by Palo Alto Networks researchers tricks people into downloading malware disguised as cracked software, stealing saved passwords while quietly running up victims' electricity bills.

3 min read
Illustration: a modern open-plan office desk at dusk
Threat Intelligence

Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs

Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

4 min read
Macro photograph of a glowing network of interconnected nodes on a dark surface, with several nodes pulsing amber-red to suggest hidden danger within an otherwi
AI Security

AI Assistants Are Inventing Fake Web Addresses — and Criminals Are Buying Them Up

Researchers at Palo Alto Networks found that AI tools routinely make up plausible-sounding website addresses that don't exist. Criminals are registering those addresses before anyone notices, and one already built a full fraud operation using the same AI trick.

4 min read
Illustration: a dark server rack aisle with faint blue and violet indicator lights, wisps of fog drifting between cabinets
Threat Intelligence

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate

Unit 42 documents a pre-positioning tactic where actors register non-existent domains that AI assistants keep suggesting, then wait for the traffic to arrive.

3 min read
Illustration: a dimly lit server room corridor in a Southeast Asian energy utility
Threat Intelligence

TinyRCT Backdoor Surfaces in CL-STA-1062 Intrusions Across Southeast Asia

Palo Alto Networks ties the previously undocumented implant to a Chinese-speaking cluster targeting state-owned energy and government entities.

2 min read
© 2026 Threat Vectr