Cortex Cloud Security Research

Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System
The offensive capabilities of large language models (LLMs) have until recently existed as theoretical risks – frequently discussed at security conferences and in conceptual industry reports, but rarely discovered in practical exploits. However, in November 2025, Anthropic published a pivotal report documenting a state-sponsored ...


Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asia

We uncovered a High severity security vulnerability CVE-2026-0628 in Google's implementation of the new Gemini feature in Chrome. This vulnerability a...


Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication

Passwordless authentication is often presented as the end of account takeover. But to unde...


Boggy Serpens Threat Assessment

We have been tracking ongoing cyberespionage campaigns by the threat group Boggy Serpens, also known as MuddyWater. Attr...


Novel Technique to Detect Cloud Threat Actor Operations

Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. The...


We discovered an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks. In this article, we explore how both intentio...


From Linear to Complex: An Upgrade in RansomHouse Encryption

Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.


In recent months, we have been analyzing the activity of an advanced persistent threat (APT) known for its espionage activities against Arabic-speakin...


Cloud Discovery With AzureHound

AzureHound is a data collection tool intended for penetration testing that is part of the BloodHound suite. Threat actors misuse this tool to enumerat...


Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign

Unit 42 stopped monitoring this threat and updating the brief on Sept. 18, 2025. Please refer to the Microsoft SharePoin...


Responding to Cloud Incidents: A Step-by-Step Guide From the 2025 Unit 42 G

Cloud incidents like ransomware attacks and account compromise can bring operations to a h...


Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR M

Phantom Taurus is a previously undocumented nation-state actor whose espionage operations align with People’s Republic of China (PRC) state interests....


Bookworm to Stately Taurus Using the Unit 42 Attribution Framework

Our research uncovered a fundamental flaw in the AI supply chain that allows attackers to gain Remote Code Execution (RCE) and additional capabilities...


Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trus

BadSuccessor is a critical attack vector that emerged following the release of Windows Server 2025. Under certain condit...