REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
41 reports · page 1 of 2

unit42 · tlp:amber · 7/17/2026, 10:00:24 AM
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 . Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research …
Read original ↗https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities
unit42 · tlp:amber · 7/16/2026, 11:00:59 PM
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42 . AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report Menu Tools ATOMs Security Consulting About Us Under A…

unit42 · tlp:amber · 7/15/2026, 10:00:54 AM
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42 . TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Thre…
Read original ↗https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet
unit42 · tlp:amber · 7/10/2026, 10:00:39 PM
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 . No Manners Here: The Ruthless Rise of The Gentlemen Ransomware Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights Hospitality Hacks and Retail Real…
Read original ↗https://unit42.paloaltonetworks.com/the-gentlemen-ransomwareunit42 · tlp:amber · 7/7/2026, 10:00:21 PM
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42 . Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation Menu Tools ATOMs Security Consulting About Us Under Attack? Thre…
Read original ↗https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysisunit42 · tlp:amber · 7/2/2026, 10:00:39 PM
How We Added WebAuthn to a Browser-Based RDP Client A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42 . How We Added WebAuthn to a Browser-Based RDP Client Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General How We Added WebAuthn to a Browser-Based RDP C…
Read original ↗https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdpunit42 · tlp:amber · 7/1/2026, 1:00:11 AM
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42 . Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Ce…
Read original ↗https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domainsunit42 · tlp:amber · 6/25/2026, 10:00:52 PM
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42 . CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Menu Tools ATOMs Security Consulting About Us Under At…
Read original ↗https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoorunit42 · tlp:amber · 6/23/2026, 10:00:51 PM
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42 . OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Cente…
Read original ↗https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-riskunit42 · tlp:amber · 6/22/2026, 10:00:04 PM
The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42 . The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Menu Tools ATOMs Se…
Read original ↗https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risksunit42 · tlp:amber · 6/20/2026, 2:05:33 AM
Threat Brief: Mitigating Large-Scale Credential Attacks We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42 . Threat Brief: Mitigating Large-Scale Credential Attacks Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats General General Th…
Read original ↗https://unit42.paloaltonetworks.com/large-scale-credential-attacksunit42 · tlp:amber · 6/16/2026, 10:00:29 AM
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42 . Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Menu Tools ATOMs Security Consulting About Us Under Attack? Threat R…
Read original ↗https://unit42.paloaltonetworks.com/hijacking-vertex-ai-modelunit42 · tlp:amber · 6/15/2026, 11:00:19 PM
Inside the Modern SOC: The 72-Minute Race Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42 . Inside the Modern SOC: The 72-Minute Race Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights Inside the Modern SOC Inside the Moder…
Read original ↗https://unit42.paloaltonetworks.com/soc-72-minute-raceunit42 · tlp:amber · 6/12/2026, 10:00:14 PM
Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here. The post Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered appeared first on Unit 42 . Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Tra…
Read original ↗https://unit42.paloaltonetworks.com/new-macos-artifact-discoveredunit42 · tlp:amber · 6/11/2026, 10:00:24 AM
Trust No Skill: Integrity Verification for AI Agent Supply Chains Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains. The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42 . Trust No Skill: Integrity Verification for AI Agent Supply Chains Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Ma…
Read original ↗https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risksunit42 · tlp:amber · 6/9/2026, 10:00:21 PM
Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion. The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42 . Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility Menu Tools ATOMs Security Consu…
Read original ↗https://unit42.paloaltonetworks.com/cloud-logging-defense-evasionunit42 · tlp:amber · 6/8/2026, 11:00:45 PM
When “Hi, This Is IT” Comes Through Microsoft Teams Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42 . When “Hi, This Is IT” Comes Through Microsoft Teams Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General When “Hi, This Is IT…
Read original ↗https://unit42.paloaltonetworks.com/microsoft-teams-phishingunit42 · tlp:amber · 6/5/2026, 2:05:42 PM
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42 . Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats Vulnerabilities Vulnerabilities Threat Brief: Active Exploitation of PAN-…
Read original ↗https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257unit42 · tlp:amber · 6/2/2026, 10:00:31 AM
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42 . Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor Menu Tools ATOMs Security…
Read original ↗https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoorunit42 · tlp:amber · 5/28/2026, 10:00:53 AM
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42 . 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Resear…
Read original ↗https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surfaceunit42 · tlp:amber · 5/27/2026, 10:00:46 PM
Out of the Crypt: The Evolving Cyber Extortion Economy Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42 . Out of the Crypt: The Evolving Cyber Extortion Economy Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Out of the Crypt: The Evolving Cyber Exto…
Read original ↗https://unit42.paloaltonetworks.com/cyber-extortion-economyunit42 · tlp:amber · 5/22/2026, 1:00:42 PM
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42 . Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Actor Grou…
Read original ↗https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpensunit42 · tlp:amber · 5/22/2026, 10:00:24 AM
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42 . Paved With Intent: ROADtools and Nation-State Tactics in the Cloud Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Cloud Cybers…
Read original ↗https://unit42.paloaltonetworks.com/roadtools-cloud-attacksunit42 · tlp:amber · 5/20/2026, 10:00:46 AM
Tracking TamperedChef Clusters via Certificate and Code Reuse Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42 . Tracking TamperedChef Clusters via Certificate and Code Reuse Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malwa…
Read original ↗https://unit42.paloaltonetworks.com/tracking-tampered-chef-clustersunit42 · tlp:amber · 5/15/2026, 10:00:52 AM
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42 . Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files Menu Tools ATOMs Security Consulting About Us Under…
Read original ↗https://unit42.paloaltonetworks.com/gremlin-stealer-evolutionunit42 · tlp:amber · 5/11/2026, 10:00:43 PM
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42 . Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Researc…
Read original ↗https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitationunit42 · tlp:amber · 5/7/2026, 12:00:53 AM
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42 . Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Me…
Read original ↗https://unit42.paloaltonetworks.com/captive-portal-zero-dayunit42 · tlp:amber · 5/5/2026, 11:00:33 PM
Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42 . Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years Menu Tools ATOMs Security Consulting About Us Under Attack? …
Read original ↗https://unit42.paloaltonetworks.com/cve-2026-31431-copy-failunit42 · tlp:amber · 5/2/2026, 12:10:33 AM
The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) appeared first on Unit 42 . The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Menu Tools ATOMs Security Consulting About Us Under Attack? English English Japanese …
Read original ↗https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacksunit42 · tlp:amber · 5/1/2026, 11:00:13 PM
Essential Data Sources for Detection Beyond the Endpoint Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42 . Essential Data Sources for Detection Beyond the Endpoint Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Essential Data Sources for Detection Be…
Read original ↗https://unit42.paloaltonetworks.com/detection-beyond-the-endpointunit42 · tlp:amber · 4/30/2026, 10:00:57 PM
That AI Extension Helping You Write Emails? It’s Reading Them First Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42 . That AI Extension Helping You Write Emails? It’s Reading Them First Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Res…
Read original ↗https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensionsunit42 · tlp:amber · 4/24/2026, 8:30:19 PM
TGR-STA-1030: New Activity in Central and South America Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. The post TGR-STA-1030: New Activity in Central and South America appeared first on Unit 42 . TGR-STA-1030: New Activity in Central and South America Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General TGR-STA-1030: New Activity in Central and South Ameri…
Read original ↗https://unit42.paloaltonetworks.com/new-activity-central-south-americaunit42 · tlp:amber · 4/23/2026, 8:45:50 PM
Frontier AI and the Future of Defense: Your Top Questions Answered What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking. The post Frontier AI and the Future of Defense: Your Top Questions Answered appeared first on Unit 42 . Frontier AI and the Future of Defense: Your Top Questions Answered Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Fr…
Read original ↗https://unit42.paloaltonetworks.com/frontier-ai-top-questions-answeredunit42 · tlp:amber · 4/23/2026, 10:00:31 AM
Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments. Learn critical insights and vital lessons for proactive security. The post Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System appeared first on Unit 42 . Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System …
Read original ↗https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacksunit42 · tlp:amber · 4/22/2026, 10:00:22 AM
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks Unit 42 research reveals AirSnitch attacks bypass WPA2/3 Wi-Fi encryption and client isolation, exposing critical infrastructure vulnerabilities. The post When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks appeared first on Unit 42 . When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks Menu Tools ATOMs Security Consulting About Us Under Attack…
Read original ↗https://unit42.paloaltonetworks.com/air-snitch-enterprise-wireless-attacksunit42 · tlp:amber · 4/20/2026, 10:00:14 AM
Fracturing Software Security With Frontier AI Models Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42 . Fracturing Software Security With Frontier AI Models Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General G…
Read original ↗https://unit42.paloaltonetworks.com/ai-software-security-risksunit42 · tlp:amber · 4/17/2026, 10:35:07 PM
Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders. The post Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) appeared first on Unit 42 . Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) Menu Tools ATOMs Security Consulting About Us U…
Read original ↗https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026unit42 · tlp:amber · 4/16/2026, 10:00:13 PM
A Deep Dive Into Attempted Exploitation of CVE-2023-33538 CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware. The post A Deep Dive Into Attempted Exploitation of CVE-2023-33538 appeared first on Unit 42 . A Deep Dive Into Attempted Exploitation of CVE-2023-33538 Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Vulnerabilities V…
Read original ↗https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538unit42 · tlp:amber · 4/8/2026, 10:00:51 PM
Cracks in the Bedrock: Agent God Mode Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks. The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42 . Cracks in the Bedrock: Agent God Mode Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Cracks in the Bedrock: Agent God Mode 8 min read Related Products Cort…
Read original ↗https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-modeunit42 · tlp:amber · 4/7/2026, 10:00:11 PM
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Unit 42 uncovers critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, demonstrating DNS tunneling and credential exposure. The post Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox appeared first on Unit 42 . Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Cracks in the Bedr…
Read original ↗https://unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-mode