An Investigation Into Years of Undetected Operations Targeting High-Value Sectors

2026-03-06T20:51:45Zbf544af476b505e51ce4c69df77096e7811abba9f0e4a07913bbee981638fe74
ai-securitycredential-theftnation-stateot-scadaphishingprompt-injectionqr-code-attacksremote-code-executionsupply-chainthreat-actor-operationswebshellszero-day

What happened

Collection of Unit 42 research and threat briefs covering multiple high-impact security issues: an ongoing investigation into cluster CL-UNK-1068 targeting high-value sectors (tunneling, reconnaissance, credential theft); active exploitation of critical/zero-day flaws including BeyondTrust RCE (CVE-2026-1731), Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340), and a high-severity Chrome Gemini bug (CVE-2026-0628); supply-chain compromise of Notepad++; SCADA privileged file system vulnerability (CVE-2025-0921); and emergent tactics such as web-based indirect prompt-injection against AI/agent

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
bf544af476b505e51ce4c69df77096e7811abba9f0e4a07913bbee981638fe74
Enrichment time
2026-03-06T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · An Investigation Into Years of Undetected Operations Targeting High-Value Sectors · Baitaphish