An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
2026-03-06T20:51:45Z•bf544af476b505e51ce4c69df77096e7811abba9f0e4a07913bbee981638fe74
ai-securitycredential-theftnation-stateot-scadaphishingprompt-injectionqr-code-attacksremote-code-executionsupply-chainthreat-actor-operationswebshellszero-day
What happened
Collection of Unit 42 research and threat briefs covering multiple high-impact security issues: an ongoing investigation into cluster CL-UNK-1068 targeting high-value sectors (tunneling, reconnaissance, credential theft); active exploitation of critical/zero-day flaws including BeyondTrust RCE (CVE-2026-1731), Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340), and a high-severity Chrome Gemini bug (CVE-2026-0628); supply-chain compromise of Notepad++; SCADA privileged file system vulnerability (CVE-2025-0921); and emergent tactics such as web-based indirect prompt-injection against AI/agent
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- bf544af476b505e51ce4c69df77096e7811abba9f0e4a07913bbee981638fe74
- Enrichment time
- 2026-03-06T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.