Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Unit 42

20 articles

Unit 42 research Amazon 2d ago

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The po...

T1041

Unit 42 → Details

Unit 42 research 2d ago

Inside the Modern SOC: Defending the Cross-Environment Pivot

Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.

Unit 42 → Details

Unit 42 research Apple 4d ago

Atomic macOS (AMOS) Stealer Activity

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.

Unit 42 → Details

Unit 42 research 6d ago

Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The p...

Unit 42 → Details

Unit 42 research Kubernetes Sep 10

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The po...

Unit 42 → Details

Unit 42 research Sep 9

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untrac...

Unit 42 → Details

Unit 42 research Sep 3

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The po...

T1041

Unit 42 → Details

Unit 42 research Sep 2

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.

Unit 42 → Details

Unit 42 research Microsoft Aug 31

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring...

T1566

Unit 42 → Details

Unit 42 research Aug 28

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Pertu...

Unit 42 → Details

Unit 42 research Aug 25

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.

Unit 42 → Details

Unit 42 research Aug 21

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The pos...

T1195

Unit 42 → Details

Unit 42 research Aug 20

Identity Abuse Through Trusted Communication Channels

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.

T1566 T1078

Unit 42 → Details

Unit 42 research Google Aug 11

Kimwolf v7: An Evolution of the Kimwolf Botnet

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: ...

T1592

Unit 42 → Details

Unit 42 research Aug 10

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The...

T1583

Unit 42 → Details

Unit 42 research Aug 7

Inside the Modern SOC: The Identity Front Door

Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.

Unit 42 → Details

Unit 42 research GitHub Aug 6

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDro...

Unit 42 → Details

Unit 42 research Aug 6

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be...

Unit 42 → Details

Unit 42 research Aug 4

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.

T1195

Unit 42 → Details

Unit 42 research Aug 4

Almost Half of Malware Samples Communicate Direct to IP

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.

Unit 42 → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA