Palo Alto Networks / Unit 42

12 items · Capability 2 · Defense 6 · Attacks 4 · all entities

Unit 42 finds two criminal clusters in Latin America running intrusions with commercial chatbots

Palo Alto Networks Unit 42 documented two activity clusters using commercial large language models, including ChatGPT and Claude, as working aids during intrusions: CL-CRI-1131, against transportation organisations, Mexican federal government ministries and Ecuadorian water utilities, and CL-CRI-1163, against Brazilian financial-sector entities. The operators left a self-hosted NextChat interface exposed on 178.128.87[.]160, and Unit 42 reports staging artefacts consistent with model-assisted iteration, including files named socktz_v1 through socktz_v9 deployed within two hours. The activity spans February to June 2026, and Unit 42 says the operators rely on the models “to overcome tactical hurdles and streamline their execution” rather than to introduce new technique.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

Unit 42 investigates an intrusion that ran more than 50 ATT&CK techniques in under ten hours

Unit 42 describes an attacker using frontier AI models and attack-specific agentic frameworks, running sub-agents in parallel across infiltration, secrets harvesting, privilege takeover, CI/CD pipeline hijacking and AI infrastructure hijacking, compressing what it calls weeks of methodical intrusion tradecraft using more than 50 MITRE ATT&CK techniques into less than 10 hours. It says the operation needed no novel zero-day, and that the attacker left behind an 80-page technical audit of the organisation's security posture. The victim is not named and has not publicly confirmed the incident.

Reported by researchersUnit 42 (Palo Alto Networks) ↗ ·

Google opens Fairwind, a vetted-access program for its cyber model and CodeMender

Fairwind limits access to Gemini 3.8 Flash Cyber and CodeMender to government and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial services, and core technology platforms, with use confined to internal cybersecurity, incident response and penetration testing staff and multi-factor authentication required. Google states more than 650 participating partners globally and names Armadin, CrowdStrike, Palo Alto Networks, Snowflake and Wiz among them.

On the recordGoogle ↗ ·

The National Cyber Director's office and Texas launch a six-month cyber pilot for water utilities

Project Watershed 250 is a six-month pilot run by the Office of the National Cyber Director with Texas Cyber Command, offering water and wastewater utilities red-team testing of current defenses, system hardening with private-sector tools, and AI tooling for utility cyber defenders. Twelve companies are named: Parsons, Microsoft, Fortinet, Google Cloud, Palo Alto Networks, Amazon Web Services, Reflection AI, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos. No number of participating utilities and no dollar figure is stated.

Reported by pressCyberScoop ↗ ·

Unit 42 reports that a few dozen neurons control an aligned model's safety refusal behaviour

Unit 42 published “perturbation probing,” a method for identifying the feed-forward neurons causally responsible for a targeted behaviour inside an aligned model, and applied it across 13 models. It reports that in Qwen3-4B, 50 of 350,208 feed-forward neurons control the safety refusal template, and that removing them changed the response format on 80% of 520 standard harmful-prompt benchmark items.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

OpenAI leads more than 100 companies in an open letter calling for collective AI cyber defense

OpenAI published an open letter, co-signed by more than 100 organizations including Anthropic, Google, Microsoft, AWS, Oracle, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks and Hugging Face, calling for collective action to defend against sustained AI-enabled attacks. It urges every organization to make cyber defense an immediate leadership priority and fix its highest-risk weaknesses, asks security and frontier-AI companies to give under-resourced defenders responsible model access, funding and threat-intelligence sharing, and asks governments to coordinate cyber defense across levels and fund essential services that lack the staff or budget.

On the recordOpenAI (open letter, 100+ signatories) ↗ ·

Unit 42 finds almost all AI-enabled malware never reaches real targets, and none evades detection

Palo Alto Networks Unit 42 analysed 405 malware samples with an AI component and reported that about 97% existed only in sandboxes or on VirusTotal; just 12 reached protected customer endpoints, and its products blocked every one. The named families that did appear in the wild (FunkSec ransomware, a trojanised 'Recipe Lister' AI app, the Oyster backdoor, Rhadamanthys and a COM-hijacking loader) were caught by the same behavioural, sandbox and endpoint mechanisms that stop conventional malware, and the firm concluded the AI component did not help the malware evade detection.

Self-reported, untestedPalo Alto Networks Unit 42 ↗ ·

OpenAI launches Daybreak, gating a cyber-tuned GPT-5.6-Cyber model to vetted security partners

OpenAI expanded its Daybreak cyber program into two partner-only access tiers: Blue, giving approved defenders access to general-purpose models including GPT-5.6 Sol with safeguards tailored to authorized defensive security work, and Red, giving access to purpose-trained cybersecurity models — a new GPT-5.6-Cyber, rated 'High' capability and below the Critical threshold — for authorized vulnerability research, exploit validation and security testing. OpenAI named SpecterOps, SentinelOne and Palo Alto Networks among the partners, who receive access to the models rather than only findings.

Self-reported, untestedOpenAI ↗ ·

Unit 42 documents stolen AI API keys resold through proxy transfer stations, with about a million dollars billed before containment

Unit 42 responded to cases in which attackers integrated exposed AI provider credentials into a proxy transfer station within minutes and ran up close to a million dollars in charges before discovery. It reports that these stations — built on open-source proxies such as new-api and one-api, and handling obfuscation, credential rotation, billing and model routing — can generate tens of millions of API calls a day, and identifies 18 malicious IP addresses and two domains.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

Unit 42 says its NOVA system found 14,090 unknown vulnerabilities across 3,915 open-source projects in two months

Palo Alto Networks' Unit 42 reported that its NOVA system, running an ensemble of frontier AI models, found 14,090 previously unknown vulnerabilities across 3,915 open-source projects over two months, saying 99.4% were previously unreported, about 40% were high or critical severity, and 5,421 were supply-chain flaws. Unit 42 said the bulk of the findings were logic and access-control classes — access-control, path-traversal and injection flaws — rather than memory-corruption bugs; the counts are the firm's own and have not been independently reproduced.

Self-reported, untestedPalo Alto Networks Unit 42 ↗ ·

Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework

Palo Alto Networks Unit 42 documented a Chinese-speaking threat actor using aliases knaithe and KnYuan who wired DeepSeek into the Hermes Agent framework and orchestrated it over Telegram to autonomously enumerate vulnerabilities, source exploits and launch attacks, including FOFA-driven scanning for exposed Langflow and n8n instances. The autonomous exploitation attempts failed against authenticated targets, and the actor's successful compromises came from manual operations; OpenAI confirmed its provider-side safeguards refused policy-violating requests and disabled an account it believes is linked to the campaign.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

NVIDIA, Microsoft, IBM, Cisco and Cloudflare launch the Open Secure AI Alliance

Thirty-seven inaugural partners — including NVIDIA, Microsoft, Adobe, Cisco, Cloudflare, Databricks, Hugging Face, IBM, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP and Snowflake, with the Linux Foundation among them — launched an alliance to share open technology for securing software and agents, contributing working code rather than recommendations: NVIDIA's NOOA agent-harness research, HPE on SPIFFE/SPIRE agent identity, Hugging Face's Safetensors, IBM and Red Hat's signed-patch supply-chain tooling, and Microsoft's MDASH scanning harness. Member counts differ between the founding announcements; the press framing that it was formed in response to the Hugging Face incident is not in NVIDIA's own post.

On the recordNVIDIA ↗ ·