Unit 42 reports endpoint alerts tied to collaboration tools more than quadrupled in 12 months, with 99% linked to chat phishing. Most controls still watch email and logins, not authenticated sessions.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence50
Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.
Reality
- Evidence55
- Adoption15
- Hype gap+20
- Incentives75
- Confidence55
Two months of AWS audit logs from 125 environments went through UMAP and HDBSCAN to group more than 40,000 identities by what they actually did, and the classification rules that fell out run in plain SQL.
Reality
- Evidence45
- Adoption18
- Hype gap+20
- Incentives80
- Confidence60
Unit 42 committed a fresh, overly permissive AWS key to a random GitHub repository with the usual quarantine policy switched off, then timed how long a cryptojacking crew took to find it and start mining.
Reality
- Evidence52
- Adoption45
- Hype gap+30
- Incentives78
- Confidence60
Palo Alto Networks is folding the startup Koi into Prisma AIRS and Cortex XDR to watch agents that run on a user's own credentials. The announcement names no incident, and Globes reported the price near $400 million.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives82
- Confidence55
Palo Alto's census says 97% of AI-enabled malware lives only in sandboxes and VirusTotal. The sampling frame and a loose definition explain much of that, and the defensive advice survives anyway.
Reality
- Evidence58
- Adoption14
- Hype gap+18
- Incentives76
- Confidence52
Unit 42 says the C++ loader reads encrypted commands from immutable smart contracts over public RPC endpoints, which turns takedown work into traffic monitoring.
Reality
- Evidence62
- Adoption28
- Hype gap+16
- Incentives72
- Confidence55