Threat Intelligence
Community feed · Research

Adversary Deep-Dives

The latest threat research aggregated from Adversary Deep-Dives — browse the feed inside NivX, click through to read the full article on the source site.

Article previews are curated from Adversary Deep-Dives. We show the title, cover image and a short snippet here; clicking any card opens the full article on the source site so the original authors get proper credit.
Threat Research

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploi…

Sep 10, 2026
Read on Research
Threat Research

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind C…

Sep 9, 2026
Read on Research
Threat Research

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Tar…

Sep 3, 2026
Read on Research
Threat Research

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside…

Sep 2, 2026
Read on Research
Threat Research

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaign…

Aug 31, 2026
Read on Research
Threat Research

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the F…

Aug 28, 2026
Read on Research
Threat Research

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2…

Aug 25, 2026
Read on Research
Threat Research

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overloo…

Aug 21, 2026
Read on Research
Threat Research

Identity Abuse Through Trusted Communication Channels

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication…

Aug 20, 2026
Read on Research
Threat Research

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. Th…

Aug 18, 2026
Read on Research
Threat Research

Kimwolf v7: An Evolution of the Kimwolf Botnet

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared…

Aug 11, 2026
Read on Research
Threat Research

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeter…

Aug 10, 2026
Read on Research
Threat Research

Inside the Modern SOC: The Identity Front Door

Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared fi…

Aug 7, 2026
Read on Research
Threat Research

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appea…

Aug 6, 2026
Read on Research
Threat Research

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first…

Aug 6, 2026
Read on Research