Logo
Unit42 Logo
  • Tools
  • ATOMs
  • Security Consulting
  • About Us
  • Under Attack?
Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.
 category iconHigh Profile Threats February 11, 2026

Nation-State Actors Exploit Notepad++ Supply Chain

Unit 42 reveals new infrastructure associated with the Notepad++ attack. This expands understanding of threat actor operations and malware delivery.

  • DLL Sideloading
  • Cobalt Strike
  • Backdoor
Read now
Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.
 category iconThreat Actor Groups February 10, 2026

A Peek Into Muddled Libra’s Operational Playbook

  • Muddled Libra
  • PowerShell
  • Scattered Spider
Read now
Close-up of a black woman with glasses examining colorful computer code on a screen. The scene is illuminated by various lights, creating a focused and analytical atmosphere.
 category iconThreat Research February 6, 2026

Novel Technique to Detect Cloud Threat Actor Operations

  • API
  • IAM
  • MITRE
Read now
Pictorial representation of the shadow campaigns. Digital graphic showing a networked globe with various data points and connectivity lines, symbolizing global digital communication and information technology.
 category iconThreat Actor Groups February 5, 2026

The Shadow Campaigns: Uncovering Global Espionage

  • Asia
  • Espionage
  • Government
Read now
Pictorial representation of a group of individuals discussing an idea with a whiteboard.
 category iconInsights February 3, 2026

Why Smart People Fall For Phishing Attacks

  • AI
  • Phishing
Read now
Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.
 category iconThreat Research January 30, 2026

Privileged File System Vulnerability Present in a SCADA System

  • CVE-2025-0921
  • Privilege escalation
  • SCADA
Read now
Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.
 category iconInsights January 29, 2026

Understanding the Russian Cyberthreat to the 2026 Winter Olympics

  • AI
  • IoT
  • Russia
Read now
Pictorial representation of orange, wave-like lines illuminated against a navy background.
 category iconInsights January 23, 2026

Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

  • Cyber Threat Alliance
  • Unit 42
Read now
Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.
 category iconThreat Research January 22, 2026

The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time

  • API
  • DeepSeek
  • Google
Read now
Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.
 category iconThreat Research January 20, 2026

DNS OverDoS: Are Private Endpoints Too Private?

  • Microsoft Azure
  • Networking
Read now
Pictorial representation of a man viewing multiple computer monitors displaying lines of code. The screens emit a blue glow against a textured pink background.
 category iconInsights January 16, 2026

Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering

  • MFA
  • Phishing
  • SEO poisoning
Read now
Pictorial representation of MongoBleed, CVE-2025-14847. Digital image featuring a glowing padlock icon superimposed on a background of streaming blue binary code, symbolizing cybersecurity.
 category iconHigh Profile Threats January 13, 2026

Threat Brief: MongoDB Vulnerability (CVE-2025-14847)

  • CVE-2025-14847
  • MongoDB
Read now
Pictorial representation of remote code execution in AI and machine learning libraries. Close-up of a woman wearing glasses and focusing intently on a computer screen.
 category iconThreat Research January 13, 2026

Remote Code Execution With Modern AI/ML Formats and Libraries

  • Apple
  • CVE-2025-23304
  • CVE-2026-22584
Read now
Loader icon View more
Newsletter
UNIT 42 Small Logo Get updates from Unit 42

Peace of mind comes from staying ahead of threats. Subscribe today.

Subscribe for email updates to all Unit 42 threat research.
By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Invalid captcha!

Get the latest news, invites to events, and threat alerts

By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks Privacy Statement and Terms of Use.

Products and Services

  • AI-Powered Network Security Platform
  • Secure AI by Design
  • Prisma AIRS
  • AI Access Security
  • Cloud Delivered Security Services
  • Advanced Threat Prevention
  • Advanced URL Filtering
  • Advanced WildFire
  • Advanced DNS Security
  • Enterprise Data Loss Prevention
  • Enterprise IoT Security
  • Medical IoT Security
  • Industrial OT Security
  • SaaS Security
  • Next-Generation Firewalls
  • Hardware Firewalls
  • Software Firewalls
  • Strata Cloud Manager
  • SD-WAN for NGFW
  • PAN-OS
  • Panorama
  • Secure Access Service Edge
  • Prisma SASE
  • Application Acceleration
  • Autonomous Digital Experience Management
  • Enterprise DLP
  • Prisma Access
  • Prisma Browser
  • Prisma SD-WAN
  • Remote Browser Isolation
  • SaaS Security
  • AI-Driven Security Operations Platform
  • Cloud Security
  • Cortex Cloud
  • Application Security
  • Cloud Posture Security
  • Cloud Runtime Security
  • Prisma Cloud
  • AI-Driven SOC
  • Cortex XSIAM
  • Cortex XDR
  • Cortex XSOAR
  • Cortex Xpanse
  • Unit 42 Managed Detection & Response
  • Managed XSIAM
  • Threat Intel and Incident Response Services
  • Proactive Assessments
  • Incident Response
  • Transform Your Security Strategy
  • Discover Threat Intelligence

Company

  • About Us
  • Careers
  • Contact Us
  • Corporate Responsibility
  • Customers
  • Investor Relations
  • Location
  • Newsroom

Popular Links

  • Blog
  • Communities
  • Content Library
  • Cyberpedia
  • Event Center
  • Manage Email Preferences
  • Products A-Z
  • Product Certifications
  • Report a Vulnerability
  • Sitemap
  • Tech Docs
  • Unit 42
  • Do Not Sell or Share My Personal Information
PAN logo
  • Privacy
  • Trust Center
  • Terms of Use
  • Documents

Copyright © 2026 Palo Alto Networks. All Rights Reserved

  • Youtube
  • Podcast
  • Facebook
  • LinkedIn
  • Twitter
  • Select your language
    Your browser does not support the video tag.

    Default Heading

    Read the article Right Arrow