Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
Unit 42 reports actor TheHatman claims large-scale theft of Microsoft Entra credentials and provides mitigation guidance for credential attacks.
Palo Alto Networks Unit 42 published an updated threat brief on mitigating large-scale credential attacks. In August 2026, the actor TheHatman claimed to have stolen a large volume of credentials from organizations' Microsoft Entra tenants. The brief outlines defensive guidance for organizations facing large-scale credential attacks. The theft claims originate from the actor and the post focuses on mitigation steps.
DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
Cloudflare's H1 2026 report shows record DDoS scale, with more 1 Tbps+ attacks, multi-vector campaigns, and hacktivist surges against governments.
Cloudflare's H1 2026 DDoS Threat Report documents record-scale attacks, with a significant increase in campaigns exceeding 1 Tbps and April 2026 peaking at 6.46 trillion requests and 165 PB. Most network-layer attacks stayed small and short — 96.62% under 500 Mbps and 90.60% under 10 minutes — but multi-vector campaigns combining HTTP floods with DNS and CLDAP amplification grew. Operation Epic Fury drove 149 hacktivist DDoS claims against 110 organizations in 16 countries, hitting the government sector hardest, and Brazil overtook the US as the leading attack source country.