Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
2026-08-19T20:51:31Z•248dec4402858f334435c0e182db03a6df498801b0a0aeac4da9d967f2887992
AI securityAI-assisted attacksAPI key theftAndroid IoTChinese-speaking threat actorDDoSEthereumGitHub ActionsMicrosoft Entra IDPolygonRussian cyberespionageTorWebAuthnXCSSETblockchain C2botnetcredential-theftdirect-to-IP C2identity-attacksmacOS malwarenpm supply-chainpasskeyssecret theftthreat-intelligencezero-day discovery
What happened
Unit 42 threat-intelligence feed covering August–July 2026 reporting on large-scale Microsoft Entra credential theft, Android IoT botnets, blockchain- and Tor-based C2, npm supply-chain worms, AI-token theft, passwordless authentication weaknesses, macOS malware, AI-assisted attacks, webmail espionage, and Siemens ROX II OT zero-day vulnerabilities. The collection includes both active campaigns and defensive research across identity, cloud, software supply chain, endpoint, and operational technology environments.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 248dec4402858f334435c0e182db03a6df498801b0a0aeac4da9d967f2887992
- Enrichment time
- 2026-08-19T20:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.