Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
2026-08-19T08:51:31Z•6ed72933192c2b29ea2a4fdc3e3218e9126c90e7b1fa90e7796b4ff2b10d9b7c
AI securityAPI-key theftAndroid IoTDDoSEthereumGitHub ActionsMicrosoft Entra IDPolygonTorXCSSETZimbraautonomous cyberattacksblockchain C2botnetcredential-attacksidentity-securitymacOS malwarenpmpasskeys מער? שאלphishingsecret-theftsoftware-supply-chainthreat-intelligencewebmail espionagezero-day
What happened
Unit 42 threat intelligence covering large-scale Microsoft Entra credential attacks, Android IoT botnets, blockchain- and Tor-based command and control, npm supply-chain worms, API-token theft, AI-assisted vulnerability discovery and cyberattacks, macOS malware, webmail espionage, passkey implementation weaknesses, and zero-day exploitation of Siemens OT switches. The collection spans identity compromise, malware, supply-chain attacks, cloud and developer credential theft, industrial control systems, and adversary use of emerging technologies.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 6ed72933192c2b29ea2a4fdc3e3218e9126c90e7b1fa90e7796b4ff2b10d9b7c
- Enrichment time
- 2026-08-19T08:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.