#unit-42
14 articles
From April 22 to August 20, 2026, ZCyberNews published 20 articles under the Unit 42 tag, covering 16 high-severity and 2 critical incidents. The reporting identified APT29, CL-STA-1062, and Gremlin Stealer as distinct threat actors. Affected sectors included technology, software development, enterprise, financial services, and government, with global impact and specific incidents in Central America, North America, South America, and South Asia.
HIGHIdentity Abuse via Trusted Chat Channels Quadruples, Unit 42 Warns
Unit 42 reports collaboration-tool identity attacks quadrupled in 12 months, with 99% of alerts tied to chat phishing. APT29 abused Microsoft Teams federation for credential theft.
HIGHToken Jacking: Cybercriminals Steal AI API Keys for Gray Market Resale
Unit 42 reports token jacking: attackers steal AI API keys to resell access on gray-market transfer stations, causing staggering financial losses for developers.
HIGHAlmost Half of Malware Samples Communicate Direct to IP
Unit 42 finds 45.32% of C2-active malware bypass DNS with direct-to-IP connections. Learn how ZT-IP enforcement blocks these evasive threats.
CRITICALFrontier AI Finds 14,090 Zero-Days in OSS in 2 Months
Unit 42's NOVA system uncovered 14,090 novel vulnerabilities across 3,915 OSS projects in two months — 40% high or critical severity — collapsing the patch window to near zero.
HIGHPass-the-Passkey Attacks Hijack Chrome Synced Accounts
Unit 42 reveals Pass-ta-key attacks: malware on Windows Chrome endpoints steals synced passkeys, bypasses biometric verification, and extracts private keys without user...
HIGHXCSSET v40 Returns: macOS Malware Hits Xcode Developers
XCSSET v40, a macOS malware targeting Xcode developers, has resurfaced with 17 modules, including a Chrome hijacking backdoor and Telegram trojanizer, after months of dormancy.
HIGHCL-STA-1062 Targets Southeast Asian Governments and Critical
Chinese-speaking threat group CL-STA-1062 compromised at least 10 Southeast Asian government and energy entities in 2025 using web shells, tunneling tools, and a new TinyRCT...
HIGHTrust No Skill: BIV Audit Finds 80% of AI Agent Skills Misbehave
Unit 42's Behavioral Integrity Verification scanned 49,943 OpenClaw skills and found 80% deviate from declared behavior, with multi-stage attack chains enabling credential theft...
HIGHGremlin Stealer Evolves: Crypto Clipping, Session Hijacking, Packed
Unit 42 details a new Gremlin stealer variant using XOR-encrypted resource sections, crypto clipper, WebSocket session hijacking, and a commercial packer with instruction...
HIGHWest Pharma Hit by Ransomware, Systems Disrupted Globally
West Pharmaceutical Services took systems offline globally after a May 4 ransomware attack with data exfiltration. Unit 42 is investigating; ransom may have been paid.
HIGHAI Browser Extensions Steal Emails, Passwords via Prompt Injection
Unit 42 finds 30+ malicious AI browser extensions exfiltrating email content, credentials, and API keys via prompt injection and DOM scraping. Affects Chrome, Edge users.
CRITICALTeamPCP Partners with Vect Ransomware in Supply Chain Attacks
Unit 42 reports TeamPCP has partnered with Vect ransomware group to target security software vendors in multi-stage supply chain attacks, compromising trusted update mechanisms.
HIGHUnit 42 Tracks TGR-STA-1030 Activity in Central and South America
Palo Alto Unit 42 reports TGR-STA-1030 remains active in Central and South America, targeting government and energy sectors with custom malware and living-off-the-land techniques.
HIGHAirSnitch Attacks Bypass WPA2/3 Encryption, Expose Enterprise Wi-Fi
Unit 42 reveals AirSnitch attacks bypass WPA2/3 encryption and client isolation, exposing enterprise Wi-Fi to packet injection and credential theft.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.