Inside the Modern SOC: The 72-Minute Race
2026-06-16T08:51:42Z•7ce8a6568022ff2e8100cf44f364e35742eca89b677839f92b14024792451710
AD CS exploitationAI agent supply chainCVE-2026-0257FlutterShellGremlin stealerIranian APTMDRMicrosoft Teams phishingPAN-OSROADtoolsSOC automationScreening SerpensTahoe 26TamperedChefWorld Cup attack surfaceXSIAMactive exploitationcloud loggingcyber extortiondefense evasionlog manipulationmacOSmalvertisingnpmsupply chain
What happened
Palo Alto Unit 42 published a batch of advisories and research covering active exploitation and broad threat trends. Key items: an active-exploitation threat brief for PAN-OS CVE-2026-0257 with IoCs and mitigations; macOS-specific research including a new Tahoe 26 forensic artifact and the FlutterShell backdoor distributed via malvertising (Operation FlutterBridge); supply-chain analyses for npm packages and AI agent “skills”; cloud-logging manipulation and defense-evasion techniques; rising Microsoft Teams phishing threats; tracking of Iranian APT Screening Serpens and ROADtools misuse in the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 7ce8a6568022ff2e8100cf44f364e35742eca89b677839f92b14024792451710
- Enrichment time
- 2026-06-16T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.