Logo
Unit42 Logo
  • Tools
  • ATOMs
  • Security Consulting
  • About Us
  • Under Attack?
Pictorial representation of Vertex AI model uploads. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.
 category iconThreat Research June 16, 2026

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more.

  • Bucket squatting
  • Google Cloud
  • Joblib
Read now
Pictorial representation of a microphone with a blurred background of an individual wearing a maroon shirt moving their hands expressively.
 category iconInsights June 15, 2026

Inside the Modern SOC: The 72-Minute Race

  • Identity
  • Operation security
  • Unit 42 Incident Response Report
Read now
Pictorial representation of an individual typing on a laptop featuring pop-up screens of lists and tasks.
 category iconInsights June 12, 2026

Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered

  • Digital forensics
  • MacOS
Read now
Pictorial representation of integrity verification for AI Agent supply chains. A swirling, colorful digital pattern on a dark background resembling a vortex. Bright dots and lines in shades of blue, pink, and purple create a dynamic, futuristic effect.
 category iconThreat Research June 11, 2026

Trust No Skill: Integrity Verification for AI Agent Supply Chains

  • AI agents
  • Credential exfiltration
  • LLMs
Read now
Pictorial representation of Cloud Logging services for defense evasion. A vibrant digital illustration depicting a glowing, neon blue cloud symbol positioned over a circuit board landscape. The cloud symbolizes cloud computing technology, and the landscape features intricate electronic circuits with glowing lines and nodes, suggesting high-tech data transfer and connectivity.
 category iconThreat Research June 9, 2026

Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility

  • AWS CloudTrail
  • Cloud logging
  • Defense evasion
Read now
Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.
 category iconHigh Profile Threats June 9, 2026

Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

  • CVE-2026-0257
  • Vulnerability
Read now
Pictorial representation of an aerial view of an individual working on a cumputer in an office setting.
 category iconInsights June 8, 2026

When “Hi, This Is IT” Comes Through Microsoft Teams

  • Cloaked Ursa
  • Identity
  • Phishing
Read now
Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.
 category iconHigh Profile Threats June 2, 2026

The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)

  • Credential Harvesting
  • GitHub
  • Npm packages
Read now
Pictorial representation of FlutterBridge. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.
 category iconThreat Research June 2, 2026

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

  • CL-CRI-1089
  • MacOS
  • Malvertising
Read now
Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.
 category iconInsights May 28, 2026

2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

  • Fiddling Scorpius
  • Fighting Ursa
  • Muddled Libra
Read now
Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.
 category iconInsights May 27, 2026

Out of the Crypt: The Evolving Cyber Extortion Economy

  • Bling Libra
  • Extortion
  • Frontier AI
Read now
Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.
 category iconThreat Actor Groups May 22, 2026

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

  • Advanced Persistent Threat
  • AppDomainManager
  • DLL Sideloading
Read now
Pictorial representation of ROADtools framework in the cloud. An Asian man wearing glasses sits in front of a computer screen. Reflecting in the glasses are lines indicating analysis. Bright blue city lights illuminate the rest of the image.
 category iconThreat Research May 22, 2026

Paved With Intent: ROADtools and Nation-State Tactics in the Cloud

  • Curious Serpens
  • Entra ID
  • Microsoft Azure
Read now
Loader icon View more
Newsletter
UNIT 42 Small Logo Get updates from Unit 42

Peace of mind comes from staying ahead of threats. Subscribe today.

Subscribe for email updates to all Unit 42 threat research.
By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Invalid captcha!

Get the latest news, invites to events, and threat alerts

By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks Privacy Statement and Terms of Use.

Products and Services
  • AI-Powered Network Security Platform
  • Secure AI by Design
  • Prisma AIRS
  • AI Access Security
  • Cloud Delivered Security Services
  • Advanced Threat Prevention
  • Advanced URL Filtering
  • Advanced WildFire
  • Advanced DNS Security
  • Enterprise Data Loss Prevention
  • Enterprise IoT Security
  • Medical IoT Security
  • Industrial OT Security
  • SaaS Security
  • Next-Generation Firewalls
  • Hardware Firewalls
  • Software Firewalls
  • Strata Cloud Manager
  • SD-WAN for NGFW
  • PAN-OS
  • Panorama
  • Secure Access Service Edge
  • Prisma SASE
  • Application Acceleration
  • Autonomous Digital Experience Management
  • Enterprise DLP
  • Prisma Access
  • Prisma Browser
  • Prisma SD-WAN
  • Remote Browser Isolation
  • SaaS Security
  • AI-Driven Security Operations Platform
  • Cloud Security
  • Cortex Cloud
  • Application Security
  • Cloud Posture Security
  • Cloud Runtime Security
  • Prisma Cloud
  • AI-Driven SOC
  • Cortex XSIAM
  • Cortex XDR
  • Cortex XSOAR
  • Cortex Xpanse
  • Unit 42 Managed Detection & Response
  • Managed XSIAM
  • Next-Generation Identity Security
  • Privileged Access Management
  • Identity and Access Management
  • Endpoint Privilege Manager
  • Identity Governance
  • Workforce Password Management
  • Agentic Identities
  • Secrets Management
  • Unified Secrets Governance
  • Application Credentials Delivery
  • Vendor Privileged Access
  • Threat Intel and Incident Response Services
  • Proactive Assessments
  • Incident Response
  • Transform Your Security Strategy
  • Discover Threat Intelligence
Company
  • About Us
  • Careers
  • Contact Us
  • Corporate Responsibility
  • Customers
  • Investor Relations
  • Location
  • Newsroom
Popular Links
  • Blog
  • Communities
  • Content Library
  • Cyberpedia
  • Event Center
  • Manage Email Preferences
  • Products A-Z
  • Product Certifications
  • Report a Vulnerability
  • Sitemap
  • Tech Docs
  • Unit 42
  • Do Not Sell or Share My Personal Information
Palo Alto Networks Logo
  • Privacy
  • Trust Center
  • Terms of Use
  • Documents

Copyright © 2026 Palo Alto Networks. All Rights Reserved

  • Youtube
  • Podcast
  • Facebook
  • LinkedIn
  • Twitter
  • Select your language
    Your browser does not support the video tag.

    Default Heading

    Read the article Right Arrow