What Happened
Security research on SequenceHash identifies a protocol flaw: hashing values after simply concatenating them erases their boundaries. Two different sequences can then produce the same hash input, potentially allowing forged Fiat–Shamir proofs or commitments that can be opened in more than one way [1].
SequenceHash addresses this by appending a 128-bit byte count…
What Happened
Microsoft’s 2026 Digital Defense Report describes attacks spanning identities, applications, cloud systems, infrastructure and software supply chains. Its findings indicate that attackers are using AI to accelerate and tailor established techniques, while both attackers and defenders use AI to find software vulnerabilities. [2]
In Microsoft’s observations, government agencies and services accounted for 27%…
What Happened
Recent security research and incident telemetry show concurrent risks across traditional infrastructure and AI/agentic security practice: appliance zero‑days in the wild, and active exploitation of internet‑facing mail services — while vendors push agentic SOC tooling and AI security features that change the threat and response surface.
Citrix NetScaler zero‑days: Unit 42…
Findings [1] 2026-09-29 Phishing Abuses RMM Tools for Persistent Access In this article Attack chain overviewMitigation and protection guidanceLearn More In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures,… The installer subsequently dropped…
Findings [1] 2026-09-28 Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit…
Findings [1] 2026-09-25 3 Consulting Myths Debunked by Unit 42 Experts Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42. [2] 2026-09-25 Storm-3168: Agentic-driven cloud attacks using…
Findings [1] 2026-09-24 Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments In this article Who is Storm-2570?Storm-2570 attack chain: From initial foothold to impactWhat Storm-2570 activity means for defendersMitigation and protection guidanceMicrosoft Defender detectionsHunting queries Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and… Storm-2570 uses…
Findings [1] 2026-09-23 Reimagining the SOC for the agentic era in Microsoft Defender The physics of cybersecurity are changing. So must the security operations center (SOC). Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework. That shift has… ISOC…
Findings [1] 2026-09-22 Unmasking EvilTokens: Getting to the root of device code phishing In this article What is device code phishing?EvilTokens platform and operationsEvilTokens phishing emailsMitigation and protection guidanceMicrosoft Defender XDR detectionsHunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals… The…
Findings [1] 2026-09-21 SAML: A fractal of bad design Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies… Despite being front and center…
What Happened
Recent industry research and audits reveal two converging classes of risk in production AI systems: (1) implementation-level bugs in cryptographic and low-level libraries that enable signature forgeries and memory-corruption style failures, and (2) agent- and model-layer configuration and prompt‑injection weaknesses that permit credential and secret exfiltration.
Concrete examples include an agent-assisted audit of…
What Happened
Recent security research and vendor incident work shows a clear pattern: AI and autonomous agents are amplifying classic weaknesses into multi-stage, cross-environment attack chains that span identities, endpoints, applications, networks and AI systems. Vendors and threat teams have documented agent escapes, credential exposure, supply‑chain abuse, device‑code phishing and impersonation campaigns that use AI…