Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Unit 42

18 articles

Unit 42 research Apple 12h ago

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.

Unit 42 → Details

Unit 42 research 1d ago

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.

Unit 42 → Details

Unit 42 research Oracle Jul 23

Russian Global Webmail Espionage

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global W...

Unit 42 → Details

Unit 42 research Jul 17

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The ...

T1548

Unit 42 → Details

Unit 42 research Jul 16

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and At...

Unit 42 → Details

Unit 42 research Jul 15

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.

Unit 42 → Details

Unit 42 research Jul 15

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.

Unit 42 → Details

Unit 42 research Jul 10

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here.

Unit 42 → Details

Unit 42 research Jul 7

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination.

Unit 42 → Details

Unit 42 research Microsoft Jul 2

How We Added WebAuthn to a Browser-Based RDP Client

A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebA...

Unit 42 → Details

Unit 42 research Jul 1

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more.

T1195

Unit 42 → Details

Unit 42 research Jun 26

Threat Brief: Mitigating Large-Scale Credential Attacks

We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The po...

Unit 42 → Details

Unit 42 research Jun 25

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor...

Unit 42 → Details

Unit 42 research Jun 23

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The ...

Unit 42 → Details

Unit 42 research Jun 22

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post Th...

T1041

Unit 42 → Details

Unit 42 research Jun 16

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more.

T1190

Unit 42 → Details

Unit 42 research Jun 15

Inside the Modern SOC: The 72-Minute Race

Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunt...

T1041

Unit 42 → Details

Unit 42 research Apple Jun 12

Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered

Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here.

Unit 42 → Details

FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA