ZeroHour
Product

Unit 42

0 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Unit 42 says a human attacker used AI agents to execute a full ransomware intrusion in under 10 hours, leaving the victim an 80-page security audit.

Palo Alto Networks Unit 42 incident responders report a human ransomware operator used frontier AI models and agentic attack frameworks to breach an enterprise in under 10 hours, work that normally takes human operators around two weeks. AI agents performed reconnaissance, breached a public API endpoint to tunnel into the network, scraped code repositories for hard-coded tokens and service passwords, then used them to steal master administrative credentials from the secret-management system for root access. Specialist pivot agents validated access to cloud, identity, CI/CD, container and SaaS environments, and the attacker hijacked CI/CD workflows to steal cloud keys and turn the victim's cloud AI services into post-compromise infrastructure. The agents left an 80-page audit detailing dozens of exploited findings.

The Register · Security · 13d agoRansomware in the wild

Code review used to be the only way to catch these bugs

Palo Alto Networks' Unit 42 says its NOVA system found 14,090 vulnerabilities in 3,915 open-source projects, mostly non-crashing bugs like access control flaws.

Unit 42's NOVA system analyzed 3,915 open-source projects over two months and reported 14,090 validated vulnerabilities, only 85 of which matched previously documented findings. 92% of findings fell outside fuzzing-friendly categories, clustering instead in access control, path traversal, injection, prototype pollution, and SSRF; language ecosystems showed distinct weakness profiles. Of 5,421 supply-chain findings, 1,280 were flaws in dependencies while 4,141 were downstream exposures, 2,776 validated with working proof-of-concepts. Unit 42 warned that faster discovery combined with an average 55-day patch deployment window has collapsed the patch-to-exploit gap.

Help Net Security · 21d agoResearch

Introducing Unit 42’s Attribution Framework

Unit 42 releases its Attribution Framework, a systematic method using Diamond Model and Admiralty scores to attribute activity clusters to named threat actors.

Palo Alto Networks' Unit 42 introduced a structured framework for threat actor attribution built on the Diamond Model of Intrusion Analysis and Admiralty reliability/credibility scoring. The framework tracks activity at three levels: activity clusters (named CL-STA, CL-CRI, CL-UNK, or CL-MIX), temporary threat groups, and named threat actors using the constellation naming schema. Analysts score evidence across TTPs, tooling, malware code, OPSEC, infrastructure, timelines, and victimology to decide when to merge or elevate clusters, avoiding premature group naming.

Palo Alto Unit 42 · 29d agoResearch

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.