[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# OperTraitors: How Kubernetes Operators Betray Your Security Posture

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Cloud](https://unit42.paloaltonetworks.com/product-category/cortex-cloud/ "Cortex Cloud")[![Unit 42 AI Security Assessment icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 AI Security Assessment](https://unit42.paloaltonetworks.com/product-category/ai-security-assessment/ "Unit 42 AI Security Assessment")[![Unit 42 Frontier AI Defense icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Frontier AI Defense](https://unit42.paloaltonetworks.com/product-category/unit-42-frontier-ai-defense/ "Unit 42 Frontier AI Defense")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Lior Yakim](https://unit42.paloaltonetworks.com/author/lior-yakim/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 29, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [AI](https://unit42.paloaltonetworks.com/tag/ai/)
  * [AI agents](https://unit42.paloaltonetworks.com/tag/ai-agents/)
  * [API](https://unit42.paloaltonetworks.com/tag/api/)
  * [GitHub](https://unit42.paloaltonetworks.com/tag/github/)
  * [Identity](https://unit42.paloaltonetworks.com/tag/identity/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/tag/vulnerabilities/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/?pdf=download&lg=en&_wpnonce=b85209d10b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/?pdf=print&lg=en&_wpnonce=b85209d10b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=OperTraitors:%20How%20Kubernetes%20Operators%20Betray%20Your%20Security%20Posture&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fagentic-ai-kubernetes-operator-risks%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fagentic-ai-kubernetes-operator-risks%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fagentic-ai-kubernetes-operator-risks%2F&title=OperTraitors:%20How%20Kubernetes%20Operators%20Betray%20Your%20Security%20Posture "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fagentic-ai-kubernetes-operator-risks%2F&text=OperTraitors:%20How%20Kubernetes%20Operators%20Betray%20Your%20Security%20Posture "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fagentic-ai-kubernetes-operator-risks%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=OperTraitors:%20How%20Kubernetes%20Operators%20Betray%20Your%20Security%20Posture%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fagentic-ai-kubernetes-operator-risks%2F "Share in Mastodon")

## Executive Summary

Kubernetes operators are coded to drastically reduce operational toil by acting as automated site reliability engineers. However, their reliance on highly privileged service accounts introduces a severe, often overlooked security weak spot.

To quantify and combat threats aiming to take advantage of this weak spot, we have released [OperTraitor](https://github.com/paloaltonetworks/opertraitor), an open-source, large language model (LLM)-powered analysis engine. OperTraitor ingests raw role-based access control (RBAC) configurations directly from locally installed operators and the OperatorHub catalog. Upon doing so, it calculates the difference between an operator's documented functionality and its actual granted privileges.

In using this tool, we discovered problems lingering in default registries like OperatorHub (e.g., abandoned, overly permissive software components). To ensure smooth deployments, developers frequently grant these Kubernetes operators broad, wildcard RBAC permissions, unintentionally transforming trusted components into silent backdoors.

OperTraitor empowers defenders by generating a normalized risk score to help visualize the potential impact of third-party operators. Defenders can then effectively downscope the operators' underlying service accounts before they can be exploited.

This article analyzes the shifting threat landscape as the industry transitions toward AI-driven agentic operators, a development that will turn these passive RBAC misconfigurations into active threat vectors.

* We detail the real-world impact of these excessive permissions through two case studies:
  * Using our tool, we identified a High-severity vulnerability (CVE-2026-6389, CVSS 8.8) in IBM's Turbonomic platform
  * OperTraitor also flagged an overly privileged configuration that included cluster-wide access to secrets and various actions on RBAC resources
* We examine the complex trade-offs vendors face between operational flexibility and strict security
* We demonstrate how to hunt for and mitigate similar risks in your own environment using OperTraitor

Palo Alto Networks customers are better protected from the threats discussed in this article through the following products:

* [Cortex Cloud](https://docs-cortex.paloaltonetworks.com/r/Cortex-CLOUD/Cortex-Cloud-Runtime-Security-Documentation/What-is-Cortex-Cloud-Identity-Security)

The [Unit 42 AI Security Assessment](https://www.paloaltonetworks.com/unit42/assess/ai-security-assessment) and [Unit 42 Frontier AI Defense](https://www.paloaltonetworks.com/unit42/ai-advantage) service can help identify and mitigate complex AI-enabled risks.

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Related Unit 42 Topics** | **[Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/), [LLM](https://unit42.paloaltonetworks.com/tag/llm/), [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/)** |

## Kubernetes Automation Mechanisms

Before we can secure Kubernetes infrastructure, we must understand its foundational automation mechanisms. When we discuss [Kubernetes operators](https://www.redhat.com/en/topics/containers/what-is-a-kubernetes-operator), we refer to two core components working in tandem, a [custom resource definition](https://kubernetes.io/docs/concepts/extend-kubernetes/api-extension/custom-resources/) (CRD) and a [controller](https://kubernetes.io/docs/concepts/architecture/controller/):

* CRD: A user-defined extension of the Kubernetes API that allows engineers to treat specific business logic (like a database cluster or a firewall policy) as a native Kubernetes object.
* Controller: A non-terminating control loop that continuously monitors the actual state of these custom resources and reconciles them against the desired state defined in the configuration files. To execute this reconciliation loop, the controller requires a Kubernetes service account bound to specific Roles or ClusterRoles.

If a threat actor compromises an operator, the scope of the compromise is entirely defined by its RBAC permissions. An overly privileged operator functions as a silent backdoor ripe for exploitation, regardless of whether the compromise stems from a container image supply chain attack, a dependency vulnerability or the hijacking of its underlying node.

## The Amplification of Risk: AI and the Agentic Era

While the fundamental issue is RBAC, the stakes are rising. The industry is currently shifting toward agentic operators, which are autonomous systems that manage clusters using LLMs and AI reasoning.

When we introduce AI into this ecosystem, excessive permissions become a much more serious weakness. We can observe this compounding risk in three emerging operational patterns:

* **LLM-enhanced logic:** Operators that enhance standard remediation with LLM calls (e.g., K8sGPT)
  * If these inherit broad RBAC, they effectively become autonomous entities capable of reading sensitive data across unintended namespaces. These autonomous entities fall under two categories:
    * External agent bridges
    * Full agent runtimes
* **External agent bridges:** Operators serving as conduits for external agents (e.g., via Model Context Protocol)
  * An overly privileged operator can grant an external AI unchecked control over cluster resources
* **Full agent runtimes:** Operators designed to manage AI agent lifecycles natively within the cluster
  * The agents' unpredictable capabilities can impact the approach to infrastructure management

Regardless of whether an operator uses an LLM or traditional deterministic logic, the defensive mandate remains the same: Secure the service account.

## Auditing the Ecosystem: The Operator Lifecycle Weak Spot

To understand the true scale of these RBAC misconfigurations across the ecosystem and empower the community to audit them, we built [OperTraitor](https://github.com/paloaltonetworks/opertraitor). We designed this automated pipeline to perform the following:

* Collect data based on [OperatorHub](https://docs.redhat.com/en/documentation/openshift_container_platform/4.3/html/operators/olm-understanding-operatorhub) and locally installed operators
* Extract their raw [YAML](https://www.redhat.com/en/topics/automation/what-is-yaml) manifests
* Feed their RBAC configurations into an LLM configured for threat analysis

The engine compares the permissions an operator actually possesses against its stated documentation. It then assigns a risk score from 1--10 based on the difference between required and granted privileges.

Figure 1 illustrates OperTraitor's high-level architecture.
![A flowchart depicting OperTraitor architecture. It includes the user interacting with both Kubernetes and Docker. The scan phase involves loading images and collecting metadata. Results are sent to an Elasticsearch server. The Analyze phase includes cross-referencing the OpenAI model and validating scores. The output displays on a web dashboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/2881-Figure-1-1.png) Figure 1. OperTraitor architecture. Source: OperTraitor repository on GitHub.

Figure 2 displays a screenshot of the OperTraitor user interface, showing the total number of high-risk operators alongside the post-analysis scores of two specific operators.
![A screenshot of OperTraitor dashboard. It includes a search bar for operators, statistics showing 631 total and analyzed operators, and 16 high risk. Two sections below provide details on specific operators, both marked with a red "10" indicating alerts. The sidebar shows categories such as Machine Learning, Big Data, and Observability.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/word-image-60156-187565-2.png) Figure 2. OperTraitor main analysis dashboard showing high-risk operators.

During this process, we uncovered a significant supply chain weakness. OperatorHub is filled with abandoned, overly permissive software components. Many vendors publish new, secure versions of their operators exclusively through [Helm charts](https://www.redhat.com/en/topics/devops/what-is-helm), their GitHub repositories or ArtifactHub. However, their older, vulnerable versions remain easily accessible through the [Operator Lifecycle Manager (OLM)](https://olm.operatorframework.io/docs/).

OLM has historically been the gold standard of the open-source community and the default in OpenShift environments. As a result, users routinely deploy outdated operators in a few simple clicks, often without realizing it. Vendors are largely not prioritizing the maintenance or deprecation of their legacy components on OperatorHub, presenting a significant attack vector.

## The Tip of the Iceberg

The RBAC misconfigurations we discovered are not isolated incidents. During our research, we identified multiple other operators (slightly over 5%) that request excessive privileges, including implicit paths to cluster admin access.

Unfortunately, many of the operator owners we contacted did not respond to our responsible disclosure attempts. In many cases, this lack of engagement simply indicates that the operator is no longer actively maintained.

While we will not cover those specific cases in this article, the reality highlights a critical takeaway that security teams must be vigilant. We strongly encourage treating every component sourced from OperatorHub with caution, independently verifying both its RBAC requirements and its active maintenance status before deployment.

To illustrate the real-world impact of these excessive permissions, we detail two specific case studies below.

### Case Study 1: Excessive Secret Access (Prometurbo Operator - IBM)

When initially scanning OperatorHub, OperTraitor flagged the Prometurbo operator for using wildcards. Recognizing that the version on OperatorHub was severely outdated (v8.6.0, from 2022), we analyzed the recent version available via IBM's GitHub repository (v8.17.6) to see if the posture had changed.

OperTraitor identified a critical RBAC violation. Instead of restricting access to its own namespace, the operator's service account was bound to a [ClusterRole](https://kubernetes.io/docs/reference/kubernetes-api/rbac/cluster-role-v1/). This ClusterRole contained an explicit rule granting get, list and watch verbs on the secrets resource within the [core API group](https://kubernetes.io/docs/reference/using-api/) (represented by apiGroups: \[""\])

Unless an operator functions explicitly as a centralized secrets manager, it rarely requires cluster-wide read access to [Secret](https://kubernetes.io/docs/reference/kubernetes-api/core/secret-v1/) resources. Typically, an operator only needs access to specific secrets within its localized namespace.

Possessing explicit, cluster-wide read access to all secrets, the Prometurbo operator effectively became a single point of failure. If compromised, an attacker could immediately dump administrative service account tokens, database credentials, API keys and TLS certificates from completely unrelated namespaces. This could turn a localized breach into a total environment compromise.

Upon identifying this setting, we initiated a responsible disclosure process with IBM. The vendor responded promptly and collaboratively, quickly identifying the root cause and issuing a patch in a subsequent release that properly scoped the operator's RBAC permissions to align with the principle of least privilege (PoLP).

Due to the importance and impact of the vulnerability, IBM published a formal [security bulletin](https://www.ibm.com/support/pages/security-bulletin-ibm-turbonomic-prometurbo-agent-used-ibm-turbonomic-application-resource-management-affected-single-vulnerability-cve-2026-6389) and assigned a CVE ([CVE-2026-6389](https://nvd.nist.gov/vuln/detail/CVE-2026-6389)) with a High CVSS score (8.8/10).

**Disclosure Timeline:**

* Nov. 5, 2025: Vulnerability reported to IBM via the Vulnerability Disclosure Program
* Feb. 3, 2026: IBM confirmed the issue is resolved
* April 24, 2026: IBM published a [security bulletin](https://www.ibm.com/support/pages/security-bulletin-ibm-turbonomic-prometurbo-agent-used-ibm-turbonomic-application-resource-management-affected-single-vulnerability-cve-2026-6389) with CVE-2026-6389

### Case Study 2: The Trade-Off Between Security and User Experience (UX) (Datadog Operator)

In the case of the Datadog operator, OperTraitor flagged an overly privileged configuration that included cluster-wide access to secrets and various actions (verbs) on RBAC resources (ClusterRoles and [ClusterRoleBindings](https://kubernetes.io/docs/reference/kubernetes-api/rbac/cluster-role-binding-v1/)).

Upon our disclosure, Datadog representatives shared a detailed explanation of the reasoning behind granting these broad permissions. They noted that the names of the secrets the operator needs to access are based on user-defined values, making them impossible to predict or explicitly define before deployment. Given Datadog's architecture, this is a valid point that highlights the complex trade-off vendors face between delivering strict security and a seamless user experience.

Datadog recognized the importance of transparency for end users assessing cluster risk. They opted to add [a detailed explanation of their RBAC settings and documented applied mitigations](https://github.com/DataDog/datadog-operator/blob/main/docs/kubernetes_permissions.md), allowing security teams to make informed risk-acceptance decisions.

## Mitigation: Securing the Non-Human Identity

Securing the operator ecosystem requires a shift in how security teams evaluate and monitor Kubernetes infrastructure. We recommend implementing the following defensive strategies:

* **Verify the source and avoid default registries:** Do not implicitly trust versions available on OLM or OperatorHub. Always verify the vendor's official documentation and deploy operators via their maintained Helm charts, ArtifactHub or official GitHub repositories to ensure you are installing the most recent, patched version.
* **Enforce namespace-scoped operators:** Whenever architecturally possible, restrict operators to the specific namespaces they manage. Avoid deploying cluster-scoped operators (ClusterRoles and ClusterRoleBindings) unless absolutely necessary, strictly limiting the area of impact in a potential compromise.
* **Continuously audit and downscope RBAC:** Always validate vendor-provided [YAML](https://yaml.org/) manifests. Assess the RBAC posture for critical production environments. There are useful open-source tools to support this task, including [OperTraitor](https://github.com/paloaltonetworks/opertraitor).
* **Monitor service account behavior:** Enable and actively monitor Kubernetes Audit Logs. Baseline the normal behavior of your operator service accounts and alert on anomalous activity. An example of anomalous activity could be an operator suddenly attempting to list secrets in an unrelated namespace or querying the API server from an unexpected IP address.
* **Establish guardrails for AI agents:** If you are experimenting with LLM enhanced operators or agentic frameworks, enforce strict network policies:
  * Ensure these pods cannot reach the public internet or unauthorized internal endpoints
  * Strictly limit the context and permissions passed to the underlying LLMs

## Conclusion

The convenience of Kubernetes operators comes with a hidden cost: the rapid proliferation of highly privileged, non-human identities within our clusters. Our research indicates a widespread violation of the PoLP across the Kubernetes ecosystem.

Whether driven by the difficulty of scoping permissions for dynamic environments or simply by a developer's misconfiguration, operators are frequently granted access that far exceeds their operational requirements. This problem is exacerbated by the prevalence of outdated, abandoned components in registries like OperatorHub, creating a massive attack surface.

The shift to agentic operators will worsen the risks this presents. An overly privileged operator today is the autonomous, uncontrolled agent of tomorrow.

As we stand on the threshold of the agentic era, the way we manage Kubernetes is undergoing a fundamental change. AI-driven automation holds incredible promise for reducing operational overhead, but it requires a rock-solid foundation of identity and access management to ensure a secure environment.

We can not afford to treat non-human identities as an afterthought. Security teams must scrutinize operator permissions with the same rigor they apply to human administrators. By improving the RBAC hygiene of our clusters today, we can safely embrace the autonomous operations of the future without betraying our security posture.

### Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Cortex Cloud](https://docs-cortex.paloaltonetworks.com/r/Cortex-CLOUD/Cortex-Cloud-Runtime-Security-Documentation/What-is-Cortex-Cloud-Identity-Security) can help protect cloud posture and runtime operations against identity-driven threats by pairing static permission baselines with deep behavioral context. By embedding the functional identity baselines discussed in this research into our detection engine for both cloud VM compute and serverless agents, Cortex Cloud adds a vital layer of operational context, enabling security teams to filter out noisy false positives and decisively catch threat actors attempting to masquerade, alter configurations, or execute anomalous operations in the environment.

The [Unit 42 AI Security Assessment](https://www.paloaltonetworks.com/unit42/assess/ai-security-assessment) and [Unit 42 Frontier AI Defense](https://www.paloaltonetworks.com/unit42/ai-advantage) service can help identify and mitigate complex AI-enabled risks.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 000 800 050 45107
* South Korea: +82.080.467.8774

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Additional Resources

* [Security Bulletin: IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability (CVE-2026-6389)](https://www.ibm.com/support/pages/security-bulletin-ibm-turbonomic-prometurbo-agent-used-ibm-turbonomic-application-resource-management-affected-single-vulnerability-cve-2026-6389) - IBM Support
* [Datadog Operator Kubernetes permissions](https://github.com/DataDog/datadog-operator/blob/main/docs/kubernetes_permissions.md) - GitHub
* [OperTraitor](https://github.com/paloaltonetworks/opertraitor) - GitHub
  Back to top

### Tags

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")
* [AI agents](https://unit42.paloaltonetworks.com/tag/ai-agents/ "AI agents")
* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")
* [GitHub](https://unit42.paloaltonetworks.com/tag/github/ "GitHub")
* [Identity](https://unit42.paloaltonetworks.com/tag/identity/ "identity")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/tag/vulnerabilities/ "Vulnerabilities")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild](https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ "Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild")

### Table of Contents

* 

### Related Articles

* [3 Consulting Myths Debunked by Unit 42 Experts](https://unit42.paloaltonetworks.com/3-consulting-myths-debunked-by-unit-42-experts/ "article - table of contents")
* [From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies](https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/ "article - table of contents")
* [Inside the Modern SOC: Defending the Cross-Environment Pivot](https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
