Inside the Modern SOC: The 72-Minute Race

2026-06-16T08:51:42Z7ce8a6568022ff2e8100cf44f364e35742eca89b677839f92b14024792451710
AD CS exploitationAI agent supply chainCVE-2026-0257FlutterShellGremlin stealerIranian APTMDRMicrosoft Teams phishingPAN-OSROADtoolsSOC automationScreening SerpensTahoe 26TamperedChefWorld Cup attack surfaceXSIAMactive exploitationcloud loggingcyber extortiondefense evasionlog manipulationmacOSmalvertisingnpmsupply chain

What happened

Palo Alto Unit 42 published a batch of advisories and research covering active exploitation and broad threat trends. Key items: an active-exploitation threat brief for PAN-OS CVE-2026-0257 with IoCs and mitigations; macOS-specific research including a new Tahoe 26 forensic artifact and the FlutterShell backdoor distributed via malvertising (Operation FlutterBridge); supply-chain analyses for npm packages and AI agent “skills”; cloud-logging manipulation and defense-evasion techniques; rising Microsoft Teams phishing threats; tracking of Iranian APT Screening Serpens and ROADtools misuse in the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
7ce8a6568022ff2e8100cf44f364e35742eca89b677839f92b14024792451710
Enrichment time
2026-06-16T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.