⤷ Title: Unit 42 Unmasks CL-STA-1087’s Years-Long Cyber Espionage Against Asian Militaries
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 01:54:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AppleChris Backdoor #APT #CL_STA_1087 #cyber_espionage #cybersecurity #infosec #MemFun Backdoor #State_Sponsored Threat #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 01:54:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AppleChris Backdoor #APT #CL_STA_1087 #cyber_espionage #cybersecurity #infosec #MemFun Backdoor #State_Sponsored Threat #threat intelligence #Unit 42
Daily CyberSecurity
Unit 42 Unmasks CL-STA-1087's Years-Long Cyber Espionage Against Asian Militaries
Unit 42 exposes CL-STA-1087, a suspected Chinese state-sponsored cyber espionage group using custom backdoors to infiltrate Asian military networks.
⤷ Title: Hijacked Accounts and AI Code: The Deadly New Playbook of Iranian APT ‘Boggy Serpens’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 01:00:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Generated Code #Boggy Serpens #Cyberespionage #cybersecurity #Hijacked Accounts #Iranian APT #phishing #Rust malware #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 01:00:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Generated Code #Boggy Serpens #Cyberespionage #cybersecurity #Hijacked Accounts #Iranian APT #phishing #Rust malware #threat intelligence #Unit 42
Daily CyberSecurity
Hijacked Accounts and AI Code: The Deadly New Playbook of Iranian APT 'Boggy Serpens'
Unit 42 reveals Iranian APT Boggy Serpens is weaponizing hijacked accounts, AI-generated code, and Rust malware to infiltrate critical infrastructure.
⤷ Title: Double Agents in the Cloud: Unit 42 Unmasks Critical AI Vulnerabilities in Google Vertex AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 08:16:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #data exfiltration #Double Agents #GCP Security #Google Cloud Platform #infosec #P4SA #Python Pickle #rce #Service Accounts #Unit 42 #Vertex AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 08:16:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #data exfiltration #Double Agents #GCP Security #Google Cloud Platform #infosec #P4SA #Python Pickle #rce #Service Accounts #Unit 42 #Vertex AI
Daily CyberSecurity
Double Agents in the Cloud: Unit 42 Unmasks Critical AI Vulnerabilities in Google Vertex AI
Unit 42 reveals how GCP Vertex AI agents can become "double agents," exfiltrating data and accessing Google’s internal code. Learn why BYOSA is essential.
⤷ Title: State-Sponsored Actors Weaponize Critical PAN-OS Zero-Day for Root
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 01:55:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #captive portal #CL_STA_1132 #CVE_2026_0300 #cyber_espionage #Edge Security #infosec #Palo Alto Networks #PAN_OS #Root RCE #Unit 42 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 01:55:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #captive portal #CL_STA_1132 #CVE_2026_0300 #cyber_espionage #Edge Security #infosec #Palo Alto Networks #PAN_OS #Root RCE #Unit 42 #zero_day
Daily CyberSecurity
State-Sponsored Actors Weaponize Critical PAN-OS Zero-Day for Root
Palo Alto Networks warns of active root RCE (CVE-2026-0300) in PAN-OS. State-sponsored cluster CL-STA-1132 is targeting edge assets. Patch and restrict now!
⤷ Title: The Zero-Detection Shadow: Unit 42 Exposes Advanced Gremlin Stealer Hijacking Live Browser WebSockets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:42:37 +0000
════════════════════════
⌗ Tags: #Malware #.NET Resource Obfuscation #Chromium Identity Theft #Code Virtualization Bytecode #Cookie Protection Bypass #Cryptojacking Clipboard Hijacker #Gremlin Stealer Malware #Unit 42 Palo Alto Networks #WebSocket Session Hijacking #XOR Encoded Payload #Zero Detection C2 Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:42:37 +0000
════════════════════════
⌗ Tags: #Malware #.NET Resource Obfuscation #Chromium Identity Theft #Code Virtualization Bytecode #Cookie Protection Bypass #Cryptojacking Clipboard Hijacker #Gremlin Stealer Malware #Unit 42 Palo Alto Networks #WebSocket Session Hijacking #XOR Encoded Payload #Zero Detection C2 Infrastructure
Information Security News
The Zero-Detection Shadow: Unit 42 Exposes Advanced Gremlin Stealer Hijacking Live Browser WebSockets - Information Security News
The exfiltration of administrative credentials and volatile session tokens increasingly manifests not as a rudimentary brute-force incursion, but as a meticulously obfuscated mechanism engineered to maintain absolute silence until the definitive moment of…
⤷ Title: Bypassing MFA: Gremlin Stealer Evolves into Advanced Memory-Resident Session Hijacker
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:26:35 +0000
════════════════════════
⌗ Tags: #Malware #Chromium Browsers #Clipboard Hijacker #Control Flow Flattening #Cyber Security #Discord Token Stealer #Gremlin Stealer #infosec #Infostealer #MFA Bypass #Session Hijacking #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:26:35 +0000
════════════════════════
⌗ Tags: #Malware #Chromium Browsers #Clipboard Hijacker #Control Flow Flattening #Cyber Security #Discord Token Stealer #Gremlin Stealer #infosec #Infostealer #MFA Bypass #Session Hijacking #Unit 42
Daily CyberSecurity
Bypassing MFA: Gremlin Stealer Evolves into Advanced Memory-Resident Session Hijacker
Unit 42 exposes the new Gremlin stealer. It uses memory-resident techniques to hijack active browser session tokens and completely bypass MFA.
⤷ Title: New Screening Serpens Cyberattacks Target Global Technology Professionals
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 12:54:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppDomain Manager Hijacking #APT group #cyber_espionage #Malware Variants #Screening Serpens #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 12:54:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppDomain Manager Hijacking #APT group #cyber_espionage #Malware Variants #Screening Serpens #threat intelligence #Unit 42
Daily CyberSecurity
New Screening Serpens Cyberattacks Target Global Technology Professionals
Learn about the latest Screening Serpens cyberattacks exposed by Unit 42. Discover their new RAT variants and advanced defensive evasion tactics.
⤷ Title: Malicious OpenClaw Skills on ClawHub Deliver Infostealers and Crypto Fraud
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Malware #agentic threats #AI supply chain #AMOS #ClawHavoc #ClawHub #Infostealer #malicious skills #OpenClaw #Palo Alto Networks #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Malware #agentic threats #AI supply chain #AMOS #ClawHavoc #ClawHub #Infostealer #malicious skills #OpenClaw #Palo Alto Networks #Unit 42
Daily CyberSecurity
Malicious OpenClaw Skills on ClawHub Deliver Infostealers and Crypto Fraud
At a glance Field Detail Actor Unattributed skill publishers; accounts banned by OpenClaw Activity Malicious AI agent skills: infostealer delivery, scanner evasion, agentic financial fraud Targets…
⤷ Title: Phantom Squatting Attacks Weaponize AI Hallucinated Domains, Unit 42 Warns
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 08:13:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI security #LLM Hallucination #Phantom Squatting #phishing #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 08:13:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI security #LLM Hallucination #Phantom Squatting #phishing #Unit 42
Daily CyberSecurity
Phantom Squatting Attacks Weaponize AI Hallucinated Domains, Unit 42 Warns
At a glance Details Activity type Phantom squatting: registering AI hallucinated domains for phishing and malware Actors Multiple suspected threat actors, including the “Montana Empire”…
⤷ Title: TuxBot v3 Evolution — an IoT Botnet Built With LLM Help
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 08:11:55 +0000
════════════════════════
⌗ Tags: #Malware #Akiru #ddos #IoT botnet #Keksec #LLM malware #TuxBot #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 08:11:55 +0000
════════════════════════
⌗ Tags: #Malware #Akiru #ddos #IoT botnet #Keksec #LLM malware #TuxBot #Unit 42
Daily CyberSecurity
TuxBot v3 Evolution — an IoT Botnet Built With LLM Help
At a glance Malware family TuxBot v3 Evolution (also tracked as Akiru) Threat actor Suspected link to the Keksec ecosystem; no confirmed named actor Target / victims IoT devices across 30+ device …
⤷ Title: Chinese Threat Actor Runs Autonomous AI Cyberattacks Using DeepSeek
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 06:30:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI security #Autonomous AI Cyberattack #Chinese Threat Actor #DeepSeek #Hermes Agent #Palo Alto Networks #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 06:30:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI security #Autonomous AI Cyberattack #Chinese Threat Actor #DeepSeek #Hermes Agent #Palo Alto Networks #threat intelligence #Unit 42
Daily CyberSecurity
Chinese Threat Actor Runs Autonomous AI Cyberattacks Using DeepSeek
At a glance Field Detail Actor Chinese-speaking operator, aliases knaithe and KnYuan Activity AI-enabled autonomous hacking campaign Targets Internet-exposed infrastructure, Chinese systems, and a…
⤷ Title: 45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:44:29 +0000
════════════════════════
⌗ Tags: #Malware #C2 Traffic #Direct_to_IP #Malware DNS Bypass #Mozi botnet #Phorpiex #SectopRAT #Unit 42 #ZT_IP Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:44:29 +0000
════════════════════════
⌗ Tags: #Malware #C2 Traffic #Direct_to_IP #Malware DNS Bypass #Mozi botnet #Phorpiex #SectopRAT #Unit 42 #ZT_IP Security
Information Security News
45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses
Many defensive systems monitor domain name queries as their primary window into outbound malicious activity – but malware families are increasingly circumventing this approach by communicati…
⤷ Title: Google Password Manager Passkey Bypasses Uncovered
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:08:43 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Google Password Manager #Passkeys #Unit 42 #windows
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:08:43 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Google Password Manager #Passkeys #Unit 42 #windows
Information Security News
Google Password Manager Passkey Bypasses Uncovered
The Transition to Passwordless Security Passwords are gradually giving way to passkeys as the primary means of digital authentication. Nevertheless, account security remains heavily dependent on h…
⤷ Title: ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:29:07 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ChainDrop #CI/CD security #npm Worm #supply chain attack #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:29:07 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ChainDrop #CI/CD security #npm Worm #supply chain attack #Unit 42
Daily CyberSecurity
ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
At a glance Malware family ChainDrop (Shai-Hulud code lineage) Threat actor Unattributed; possible link to TeamPCP (not confirmed) Targets Developer workstations, CI pipelines, cloud environments …