ZCyberNews
中文

#unit-42

14 articles

From April 22 to August 20, 2026, ZCyberNews published 20 articles under the Unit 42 tag, covering 16 high-severity and 2 critical incidents. The reporting identified APT29, CL-STA-1062, and Gremlin Stealer as distinct threat actors. Affected sectors included technology, software development, enterprise, financial services, and government, with global impact and specific incidents in Central America, North America, South America, and South Asia.

Chart showing rising collaboration tool alerts over 12 monthsHIGH
Malware

Identity Abuse via Trusted Chat Channels Quadruples, Unit 42 Warns

Unit 42 reports collaboration-tool identity attacks quadrupled in 12 months, with 99% of alerts tied to chat phishing. APT29 abused Microsoft Teams federation for credential theft.

4 min readAPT29
Diagram showing stolen AI API tokens being resold on gray-market transfer stationsHIGH
Malware

Token Jacking: Cybercriminals Steal AI API Keys for Gray Market Resale

Unit 42 reports token jacking: attackers steal AI API keys to resell access on gray-market transfer stations, causing staggering financial losses for developers.

3 min read
Network diagram showing malware connecting directly to an IP address, bypassing DNSHIGH
Malware

Almost Half of Malware Samples Communicate Direct to IP

Unit 42 finds 45.32% of C2-active malware bypass DNS with direct-to-IP connections. Learn how ZT-IP enforcement blocks these evasive threats.

5 min readPhorpiex
Abstract visualization of AI analyzing open-source code for vulnerabilitiesCRITICAL
AI Security

Frontier AI Finds 14,090 Zero-Days in OSS in 2 Months

Unit 42's NOVA system uncovered 14,090 novel vulnerabilities across 3,915 OSS projects in two months — 40% high or critical severity — collapsing the patch window to near zero.

4 min read
Diagram showing malware intercepting Chrome passkey authentication flow on WindowsHIGH
Malware

Pass-the-Passkey Attacks Hijack Chrome Synced Accounts

Unit 42 reveals Pass-ta-key attacks: malware on Windows Chrome endpoints steals synced passkeys, bypasses biometric verification, and extracts private keys without user...

3 min read
Diagram of XCSSET v40 infection chain showing stages from malicious Xcode project to in-memory execution.HIGH
Malware

XCSSET v40 Returns: macOS Malware Hits Xcode Developers

XCSSET v40, a macOS malware targeting Xcode developers, has resurfaced with 17 modules, including a Chrome hijacking backdoor and Telegram trojanizer, after months of dormancy.

5 min readXCSSET
Map of Southeast Asia with highlighted government and energy sector icons, representing CL-STA-1062 targetingHIGH
Malware

CL-STA-1062 Targets Southeast Asian Governments and Critical

Chinese-speaking threat group CL-STA-1062 compromised at least 10 Southeast Asian government and energy entities in 2025 using web shells, tunneling tools, and a new TinyRCT...

4 min readCL-STA-1062
Diagram showing AI agent skill audit pipeline comparing declared vs actual behavior across metadata, code, and instructions.HIGH
Malware

Trust No Skill: BIV Audit Finds 80% of AI Agent Skills Misbehave

Unit 42's Behavioral Integrity Verification scanned 49,943 OpenClaw skills and found 80% deviate from declared behavior, with multi-stage attack chains enabling credential theft...

3 min read
Gremlin Stealer Evolves: Crypto Clipping, Session Hijacking, PackedHIGH
Malware

Gremlin Stealer Evolves: Crypto Clipping, Session Hijacking, Packed

Unit 42 details a new Gremlin stealer variant using XOR-encrypted resource sections, crypto clipper, WebSocket session hijacking, and a commercial packer with instruction...

5 min readGremlin Stealer
West Pharma Hit by Ransomware, Systems Disrupted GloballyHIGH
Industry News

West Pharma Hit by Ransomware, Systems Disrupted Globally

West Pharmaceutical Services took systems offline globally after a May 4 ransomware attack with data exfiltration. Unit 42 is investigating; ransom may have been paid.

2 min readLockBit
AI Browser Extensions Steal Emails, Passwords via Prompt InjectionHIGH
Threat Intel

AI Browser Extensions Steal Emails, Passwords via Prompt Injection

Unit 42 finds 30+ malicious AI browser extensions exfiltrating email content, credentials, and API keys via prompt injection and DOM scraping. Affects Chrome, Edge users.

3 min read
TeamPCP Partners with Vect Ransomware in Supply Chain AttacksCRITICAL
Threat Intel

TeamPCP Partners with Vect Ransomware in Supply Chain Attacks

Unit 42 reports TeamPCP has partnered with Vect ransomware group to target security software vendors in multi-stage supply chain attacks, compromising trusted update mechanisms.

2 min readTeamPCP
Unit 42 Tracks TGR-STA-1030 Activity in Central and South AmericaHIGH
Threat Intel

Unit 42 Tracks TGR-STA-1030 Activity in Central and South America

Palo Alto Unit 42 reports TGR-STA-1030 remains active in Central and South America, targeting government and energy sectors with custom malware and living-off-the-land techniques.

2 min readTGR-STA-1030
AirSnitch Attacks Bypass WPA2/3 Encryption, Expose Enterprise Wi-FiHIGH
Threat Intel

AirSnitch Attacks Bypass WPA2/3 Encryption, Expose Enterprise Wi-Fi

Unit 42 reveals AirSnitch attacks bypass WPA2/3 encryption and client isolation, exposing enterprise Wi-Fi to packet injection and credential theft.

3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.