Logo
Unit42 Logo
  • Tools
  • ATOMs
  • Security Consulting
  • About Us
  • Under Attack?
Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.
 category iconThreat Actor Groups May 22, 2026

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns.

  • Advanced Persistent Threat
  • AppDomainManager
  • DLL Sideloading
Read now
Pictorial representation of ROADtools framework in the cloud. An Asian man wearing glasses sits in front of a computer screen. Reflecting in the glasses are lines indicating analysis. Bright blue city lights illuminate the rest of the image.
 category iconThreat Research May 22, 2026

Paved With Intent: ROADtools and Nation-State Tactics in the Cloud

  • Curious Serpens
  • Entra ID
  • Microsoft Azure
Read now
Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.
 category iconHigh Profile Threats May 21, 2026

The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21)

  • Credential Harvesting
  • GitHub
  • Npm packages
Read now
Pictorial representation of TamperedChef clusters. Hands typing on a laptop keyboard with colorful lines of binary code and digital information flowing from the screen.
 category iconThreat Research May 20, 2026

Tracking TamperedChef Clusters via Certificate and Code Reuse

  • Adware
  • Appsuite PDF
  • Certificates
Read now
Pictorial representation of Gremlin Stealer hiding in plain sight. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.
 category iconThreat Research May 15, 2026

Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

  • API
  • Cryptocurrency
  • Gremlin stealer
Read now
Pictorial representation of AD CS attacks. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.
 category iconThreat Research May 11, 2026

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

  • Active Directory
  • AD CS attacks
  • Certificate template
Read now
Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.
 category iconHigh Profile Threats May 6, 2026

Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution

  • CVE-2026-0300
  • EarthWorm
  • PAN-OS
Read now
Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.
 category iconHigh Profile Threats May 5, 2026

Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years

  • Containers
  • CVE-2026-31431
  • Kubernetes
Read now
Pictorial representation of a woman with glasses viewing a monitor with colored code.
 category iconInsights May 1, 2026

Essential Data Sources for Detection Beyond the Endpoint

  • Cloud Security
  • IAM
  • Incident response
Read now
Pictorial representation of high-risk GenAI and agentic browser extensions. A person interacts with a digital screen displaying an AI symbol, circuit patterns, and various technology icons.
 category iconThreat Research April 30, 2026

That AI Extension Helping You Write Emails? It’s Reading Them First

  • AI browser
  • Browser extension
  • GenAI
Read now
Pictorial representation of a holographic blue globe surrounded by glowing red and blue lights.
 category iconInsights April 24, 2026

TGR-STA-1030: New Activity in Central and South America

  • TGR-STA-1030
Read now
Two individuals are standing on a curved balcony inside a modern building, looking at a laptop displaying charts. The interior design features multiple layers with wooden railings and a central spiral staircase.
 category iconInsights April 23, 2026

Frontier AI and the Future of Defense: Your Top Questions Answered

  • GenAI
  • LLM
  • N-day
Read now
Pictorial representation of autonomous AI attack in cloud environments. Digital illustration of a glowing blue brain connected to a network of lines and lights.
 category iconThreat Research April 23, 2026

Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System

  • AI
  • Cloud
  • Data exfiltration
Read now
Loader icon View more
Newsletter
UNIT 42 Small Logo Get updates from Unit 42

Peace of mind comes from staying ahead of threats. Subscribe today.

Subscribe for email updates to all Unit 42 threat research.
By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Invalid captcha!

Get the latest news, invites to events, and threat alerts

By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks Privacy Statement and Terms of Use.

Products and Services
  • AI-Powered Network Security Platform
  • Secure AI by Design
  • Prisma AIRS
  • AI Access Security
  • Cloud Delivered Security Services
  • Advanced Threat Prevention
  • Advanced URL Filtering
  • Advanced WildFire
  • Advanced DNS Security
  • Enterprise Data Loss Prevention
  • Enterprise IoT Security
  • Medical IoT Security
  • Industrial OT Security
  • SaaS Security
  • Next-Generation Firewalls
  • Hardware Firewalls
  • Software Firewalls
  • Strata Cloud Manager
  • SD-WAN for NGFW
  • PAN-OS
  • Panorama
  • Secure Access Service Edge
  • Prisma SASE
  • Application Acceleration
  • Autonomous Digital Experience Management
  • Enterprise DLP
  • Prisma Access
  • Prisma Browser
  • Prisma SD-WAN
  • Remote Browser Isolation
  • SaaS Security
  • AI-Driven Security Operations Platform
  • Cloud Security
  • Cortex Cloud
  • Application Security
  • Cloud Posture Security
  • Cloud Runtime Security
  • Prisma Cloud
  • AI-Driven SOC
  • Cortex XSIAM
  • Cortex XDR
  • Cortex XSOAR
  • Cortex Xpanse
  • Unit 42 Managed Detection & Response
  • Managed XSIAM
  • Next-Generation Identity Security
  • Privileged Access Management
  • Identity and Access Management
  • Endpoint Privilege Manager
  • Identity Governance
  • Workforce Password Management
  • Agentic Identities
  • Secrets Management
  • Unified Secrets Governance
  • Application Credentials Delivery
  • Vendor Privileged Access
  • Threat Intel and Incident Response Services
  • Proactive Assessments
  • Incident Response
  • Transform Your Security Strategy
  • Discover Threat Intelligence
Company
  • About Us
  • Careers
  • Contact Us
  • Corporate Responsibility
  • Customers
  • Investor Relations
  • Location
  • Newsroom
Popular Links
  • Blog
  • Communities
  • Content Library
  • Cyberpedia
  • Event Center
  • Manage Email Preferences
  • Products A-Z
  • Product Certifications
  • Report a Vulnerability
  • Sitemap
  • Tech Docs
  • Unit 42
  • Do Not Sell or Share My Personal Information
Palo Alto Networks Logo
  • Privacy
  • Trust Center
  • Terms of Use
  • Documents

Copyright © 2026 Palo Alto Networks. All Rights Reserved

  • Youtube
  • Podcast
  • Facebook
  • LinkedIn
  • Twitter
  • Select your language
    Your browser does not support the video tag.

    Default Heading

    Read the article Right Arrow