Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Kimwolf v7: An Evolution of the Kimwolf Botnet
5+ day, 1+ hour ago (1602+ words) We are providing a content warning because the following article contains usage of a racial slur by a threat actor, which Unit 42 does not condone in any instance. We have partially redacted the racial slur, but preserved some references to…...
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
5+ day, 13+ hour ago (1633+ words) Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Highlights…...
Inside the Modern SOC: The Identity Front Door
1+ week, 1+ day ago (511+ words) In The 72-Minute Race, we explored how attackers are compressing the time between initial access and business impact. But as attacks continue to accelerate, another trend has emerged: Attackers are increasingly gaining access through compromised identities rather than exploiting technology…...
ChainDrop: Inside a Self-Propagating npm Worm
1+ week, 2+ day ago (1699+ words) Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Highlights…...
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
1+ week, 3+ day ago (1216+ words) It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys…...
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
1+ week, 4+ day ago (1315+ words) Frontier AI is fundamentally shifting the dynamics of cybersecurity — accelerating both how vulnerabilities are discovered and how quickly they can be exploited. In response to these significant results, we are actively partnering with open-source maintainers and clearinghouses such as Lightwell…...
Almost Half of Malware Samples Communicate Direct to IP
1+ week, 4+ day ago (1196+ words) Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a…...
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
1+ week, 5+ day ago (1665+ words) After decades of breaches and billions in losses, the attack vectors that defined the era of passwords and shared secrets are finally starting to fade. Passkeys replace passwords and traditional multi-factor authentication (MFA) with public-key cryptography, decreasing entire classes of…...
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
2+ week, 2+ day ago (1668+ words) After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint. V40 further enhances its detection evasion capabilities by combining polymorphic…...
Russian Global Webmail Espionage
3+ week, 2+ day ago (533+ words) Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Highlights…...