Inside the Modern SOC: Defending the Cross-Environment Pivot

2026-09-18T08:51:33Z•55f90a9eed64a84fec52a6b50f7a8b9ecd781a82b7be8be5dce4864e921e5ddd
AI-assisted attacksAI-enabled malwareAMOSAndroid IoT botnet DDoS-attackers blockchain C2Atomic macOS StealerCI/CD securityKubernetesMicrosoft Entra IDMicrosoft Teams phishingSEO poisoningSOCSPIFFESPIREUnit 42YouTube lurescloud identitycredential theftcross-environment attacksdata exfiltrationidentity spoofingmacOS malwaremulti-payload malwaresupply-chain securitythreat-intelligencevoice phishing

What happened

Unit 42 threat intelligence covering cross-environment SOC defense, macOS credential-stealing malware, cloud and workload identity abuse, Kubernetes SPIFFE/SPIRE impersonation, commodity malware delivery, AI-assisted attacks and malware, collaboration-channel phishing, large-scale Entra credential attacks, SDLC supply-chain risks, Android/IoT botnets, and blockchain-based command-and-control. The feed is primarily strategic and campaign-focused; no specific CVE identifiers are provided.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
55f90a9eed64a84fec52a6b50f7a8b9ecd781a82b7be8be5dce4864e921e5ddd
Enrichment time
2026-09-18T08:51:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.