Palo Alto Networks pointed Anthropic's unreleased Mythos at its own systems and found 75 vulnerabilities in a month, against a usual rate below five. The defense business it built on that result depends on Anthropic's model and on customers choosing a security vendor over the lab.
Reality
- Evidence45
- Adoption30
- Hype gap+35
- Incentives80
- Confidence50
Unit 42 open-sourced OperTraitor, a Kubernetes operator RBAC scanner, and used it to find CVE-2026-6389, rated CVSS 8.8, in IBM's Turbonomic. An attacker who gets into an operator inherits its service account's permissions, so those grants decide how far a single compromise reaches.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence45
Unit 42 reports endpoint alerts tied to collaboration tools more than quadrupled in 12 months, with 99% linked to chat phishing. Most controls still watch email and logins, not authenticated sessions.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence50
Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.
Reality
- Evidence55
- Adoption15
- Hype gap+20
- Incentives75
- Confidence55
September's wave altered more than 500 npm package versions and November's backdoored 796, both by republishing under a fresh version number, which is exactly the thing an exact pin declines to fetch.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Unit 42 worked a ransomware intrusion where the operator handed tactical execution to frontier AI agents, and the chain from a public API endpoint to stolen cloud AI keys closed inside a single working day with no zero-day.
Reality
- Evidence50
- Adoption20
- Hype gap+25
- Incentives60
- Confidence55
Unit 42 says the crew reached more than 150 employees at ten or more companies without a single software exploit, which puts Teams federation policy and NTLM relay hardening in scope and leaves the endpoint downstream.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 65%
- Investor
- Investor 7%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence60
SHA pinning drew a clean line through the tj-actions compromise, and then Dependabot began bumping hashes faster than anyone could read them. The claim worth enforcing is the version comment that nothing verifies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence58
According to Microsoft Threat Intelligence, every stage after the consent prompt runs on software the environment already trusts, which puts the choke point on Teams federation policy and remote-support install rights.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence65
Malwarebytes found a page promising 10,000 free months of Claude Max that skips the card and collects Google logins through a fake browser window loaded from a rented, actively maintained widget.
Reality
- Evidence58
- Adoption40
- Hype gap+12
- Incentives62
- Confidence66
AWS closed Unit 42's AgentCore finding as informative and put tool scoping on the customer. Every step the agent took to leak the token was a capability someone granted it on purpose. That moves the control into the grant list.
Reality
- Evidence36
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence45
Unit 42 traced AWSCompromisedKeyQuarantine through three versions since August 2020 and documented the GitHub secret scanning integration that lets AWS attach the policy to an exposed IAM user automatically, with the owner notified afterwards.
Reality
- Evidence62
- Adoption58
- Hype gap+8
- Incentives68
- Confidence55
Palo Alto Networks Unit 42 says the pay-per-install marketplace fed gamers and professionals into the same loader, OfferLoader, and its trojanized installers reached corporate endpoints at critical infrastructure and government entities.
Reality
- Evidence45
- Adoption58
- Hype gap+10
- Incentives70
- Confidence52
AgentCore Harness enables a root bash tool in every session unless allowedTools says otherwise. AWS closed Unit 42's report as informative, so the scoping falls to whoever declares the agent.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+22
- Incentives68
- Confidence58
The figure is Palo Alto Networks' own, drawn from investigations where a single endpoint alert turned out to be one leg of an intrusion running through cloud, identity and SaaS at the same time.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+32
- Incentives88
- Confidence46
The actor compromised a cloud environment first and built the framework inside it. The scanning and address rotation ran with little human involvement. The credentials collected belonged to other companies.
Reality
- Evidence38
- Adoption32
- Hype gap+40
- Incentives88
- Confidence55
Palo Alto's Unit 42 says a human directing AI agents went from a public API endpoint to cloud keys in under 10 hours in summer 2026. The control that blocked the backdoor attempt was a repository setting.
Reality
- Evidence52
- Adoption22
- Hype gap+18
- Incentives75
- Confidence55
Unit 42 followed the copy-paste instructions on Aug. 5, 2026, and watched one Zsh command install AMOS twice over and package a lab Mac's wallet folders and cloud credentials into a single zip.
Reality
- Evidence70
- Adoption30
- Hype gap−10
- Incentives40
- Confidence62
Two months of AWS audit logs from 125 environments went through UMAP and HDBSCAN to group more than 40,000 identities by what they actually did, and the classification rules that fell out run in plain SQL.
Reality
- Evidence45
- Adoption18
- Hype gap+20
- Incentives80
- Confidence60
Unit 42 committed a fresh, overly permissive AWS key to a random GitHub repository with the usual quarantine policy switched off, then timed how long a cryptojacking crew took to find it and start mining.
Reality
- Evidence52
- Adoption45
- Hype gap+30
- Incentives78
- Confidence60
Earlier coverage
- Prompt injection embedded in malware turns an LLM scanner's refusal into a free pass
Security · September 11, 2026 · 1 publisher
- Palo Alto Networks finds 37% of organizations can revoke an AI agent's credentials
Product · September 10, 2026 · 1 publisher
- Root on a Kubernetes node makes the SPIRE agent sign a neighbour's identity for you
Security · September 10, 2026 · 1 publisher
- Unit 42 pulled a two-year pay-per-install marketplace out of two dismissible adware tickets
Security · September 9, 2026 · 1 publisher
- Unit 42 clocked data leaving inside the first hour in nearly a fifth of its 2024 cases
Product · September 6, 2026 · 1 publisher
- Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours
Science · September 5, 2026 · 2 publishers
- Unit 42's ten-hour intrusion forces a choice about who may disable an account without asking
Leadership · September 5, 2026 · 1 publisher
- Prince of Persia parks a reserve of registered domains on its own nameservers
Security · September 4, 2026 · 1 publisher
- Cloudflare turns OpenAI's cyber model into WAF rules that wait on human approval
Product · September 3, 2026 · 1 publisher
- Unit 42 finds attacker-hosted NextChat in Mexico-Ecuador intrusion cluster, AI-enabled tools in second Brazil campaign
Security · September 3, 2026 · 1 publisher
- Gambling Goblin turns .gov.br servers into invisible reverse proxies for app-store phishing
Security · September 2, 2026 · 3 publishers
- Spring Ring stands up an onmicrosoft.com tenant to place the IT help-desk call
Build · August 31, 2026 · 1 publisher
- Every one of thirteen named 2025-26 incidents ran on a credential that still worked
Build · August 31, 2026 · 1 publisher
- Unit 42 locates Qwen3-4B's refusal template in 50 of 350,208 neurons
Security · August 28, 2026 · 1 publisher
- TeamPCP hid its infostealer inside the scanners that audit everyone else's code
Science · August 28, 2026 · 1 publisher
- Unit 42 counted 405 AI malware samples. Twelve reached a real endpoint.
Science · August 27, 2026 · 1 publisher
- AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild
Build · August 24, 2026 · 1 publisher
- Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build
Security · August 21, 2026 · 1 publisher
- Palo Alto closes CyberArk, and privileged access becomes a bundle line item
Product · August 21, 2026 · 1 publisher
- "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor
Security · August 18, 2026 · 1 publisher
- Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures
Security · August 18, 2026 · 1 publisher
- Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout
Build · August 16, 2026 · 1 publisher
- Seven agentic AI incidents, one front door: the identity metadata you publish on purpose
Security · August 14, 2026 · 2 publishers
- Kimwolf's new flood wears Chrome's fingerprints and takes orders from a blockchain
Security · August 14, 2026 · 1 publisher
- One console, two businesses: Broadcom says Jewelbug runs espionage and crypto fraud together
Security · August 14, 2026 · 1 publisher
- Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize
Security · August 14, 2026 · 1 publisher