Voice phishing moves into enterprise chat
Unit 42 has detailed a campaign it calls Spring Ring, a Microsoft Teams-based voice phishing operation observed between January and April 2026. The company says attackers used external Teams accounts to pose as IT help desk personnel and approached more...
Unit 42 maps a thin safety layer inside aligned LLMs
Unit 42 says new research found that some aligned large language models may concentrate safety refusal behavior in very small sets of feed-forward neurons. The work introduces perturbation probing, a diagnostic designed to locate internal...
Unit 42 measures the gap between AI malware samples and operations
Unit 42 says AI-enabled malware is real, but its latest dataset suggests most public samples are not yet showing up as live operational threats. The Palo Alto Networks threat research team analyzed 405 unique hashes and found...
Developer tooling is now part of the attack surface
Unit 42 says software supply chain attacks are moving deeper into the software development lifecycle, beyond finished application code. Its August 2026 research describes attackers targeting CI/CD pipelines, package ecosystems, developer...
Credential campaigns test the identity perimeter
Unit 42 has updated its threat brief on large-scale credential attacks, warning that identity systems and exposed remote services remain a practical route into enterprise environments. The report links two recent areas of concern: unverified...
SOC Teams Confront the Identity Front Door
Unit 42 says identity weaknesses played a role in nearly 90% of incidents it investigated, making accounts, sessions and access workflows a primary security concern for modern SOC teams. The firm also says 65% of initial access activity involved...
Stolen AI API Keys Become a Billing and Abuse Risk
Unit 42 says cybercriminals are stealing developer API keys for AI platforms and using them to consume or resell model access. The security team describes the activity as token jacking, an AI-focused version of stealing access to paid computing...
Autonomous AI vulnerability research moves from theory to scale
Unit 42 says an autonomous research system called NOVA confirmed 14,090 vulnerabilities across 3,915 open-source projects in two months. The company describes the work as evidence that frontier AI can expand vulnerability discovery...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.