Unit 42

  1. Spring Ring vishing campaign targets Microsoft Teams users

    Spring Ring vishing campaign targets Microsoft Teams users

    Voice phishing moves into enterprise chat Unit 42 has detailed a campaign it calls Spring Ring, a Microsoft Teams-based voice phishing operation observed between January and April 2026. The company says attackers used external Teams accounts to pose as IT help desk personnel and approached more...
  2. LLM safety fragility measured in Unit 42 neuron study of refusals

    LLM safety fragility measured in Unit 42 neuron study of refusals

    Unit 42 maps a thin safety layer inside aligned LLMs Unit 42 says new research found that some aligned large language models may concentrate safety refusal behavior in very small sets of feed-forward neurons. The work introduces perturbation probing, a diagnostic designed to locate internal...
  3. AI Malware Study Finds Few Samples Reaching Real Endpoints

    AI Malware Study Finds Few Samples Reaching Real Endpoints

    Unit 42 measures the gap between AI malware samples and operations Unit 42 says AI-enabled malware is real, but its latest dataset suggests most public samples are not yet showing up as live operational threats. The Palo Alto Networks threat research team analyzed 405 unique hashes and found...
  4. Software supply chain attacks move into developer tools

    Software supply chain attacks move into developer tools

    Developer tooling is now part of the attack surface Unit 42 says software supply chain attacks are moving deeper into the software development lifecycle, beyond finished application code. Its August 2026 research describes attackers targeting CI/CD pipelines, package ecosystems, developer...
  5. Credential Attacks Put Identity Controls Under Fresh Strain

    Credential Attacks Put Identity Controls Under Fresh Strain

    Credential campaigns test the identity perimeter Unit 42 has updated its threat brief on large-scale credential attacks, warning that identity systems and exposed remote services remain a practical route into enterprise environments. The report links two recent areas of concern: unverified...
  6. Identity-Based Attacks Drove Nearly 90% of Unit 42 Cases

    Identity-Based Attacks Drove Nearly 90% of Unit 42 Cases

    SOC Teams Confront the Identity Front Door Unit 42 says identity weaknesses played a role in nearly 90% of incidents it investigated, making accounts, sessions and access workflows a primary security concern for modern SOC teams. The firm also says 65% of initial access activity involved...
  7. AI token jacking turns stolen API keys into gray market access

    AI token jacking turns stolen API keys into gray market access

    Stolen AI API Keys Become a Billing and Abuse Risk Unit 42 says cybercriminals are stealing developer API keys for AI platforms and using them to consume or resell model access. The security team describes the activity as token jacking, an AI-focused version of stealing access to paid computing...
  8. AI vulnerability discovery finds 14,090 open-source flaws

    AI vulnerability discovery finds 14,090 open-source flaws

    Autonomous AI vulnerability research moves from theory to scale Unit 42 says an autonomous research system called NOVA confirmed 14,090 vulnerabilities across 3,915 open-source projects in two months. The company describes the work as evidence that frontier AI can expand vulnerability discovery...
Top