| 1 | Threat / Category IoT botnet evolution TuxBot v3 uses LLM-assisted development inside an operational IoT botnet framework[3]Evidence dated Jul 15, 2026 | Why it mattersUnit 42's analysis places AI assistance alongside C2, DGA, and containerized deployment. The defensive conclusion is to monitor the resulting behavior and infrastructure without overstating autonomous AI operation. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 2 | Threat / Category Ransomware operation The Gentlemen are becoming a durable ransomware operating model[4]Evidence dated Jul 10, 2026 | Why it mattersUnit 42's analysis connects the operation to RaaS behavior and related Scorpius clusters. Defenders should follow access, evasion, exfiltration, and encryption behaviors rather than waiting for one brand name. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 3 | Threat / Category Infostealer campaign Vidar combines code-signing abuse, Go loaders, file inflation, and miner delivery[5]Evidence dated Jul 7, 2026 | Why it mattersUnit 42's campaign analysis shows a layered execution and evasion chain. Certificate trust, loader behavior, oversized-file heuristics, credential theft, and secondary payloads should be correlated. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 4 | Threat / Category Software supply chain AI-hallucinated domains can become dependency-confusion infrastructure[6]Evidence dated Jun 30, 2026 | Why it mattersPhantom squatting turns nonexistent package or domain suggestions into attacker-controlled names. Development pipelines need approved registries, dependency verification, and monitoring for newly registered references. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 5 | Threat / Category Credential campaign Large-scale password spraying targets Fortinet, Sophos, and MSSQL services[7]Evidence dated Jun 26, 2026 | Why it mattersUnit 42 observed spraying, configuration extraction, offline cracking, and credential reuse. A forum seller claimed responsibility, but Unit 42 explicitly said it had not validated that claim. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 6 | Threat / Category Nation-state activity cluster CL-STA-1062 targets Southeast Asian government and critical infrastructure[8]Evidence dated Jun 25, 2026 | Why it mattersUnit 42's cluster reporting and TinyRAT-related backdoor analysis provide a behavior-led detection and scoping path while preserving the cluster-level attribution boundary. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 7 | Threat / Category AI supply chain OpenClaw's skill marketplace expands software trust into agent capabilities[9]Evidence dated Jun 23, 2026 | Why it mattersUnit 42 shows how AI skills and marketplaces can introduce malicious or over-privileged behavior. Organizations need provenance, permission review, sandboxing, and runtime visibility for agent tools. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 8 | Threat / Category Cloud data exfiltration Universal bucket hijacking turns namespace reuse into a data-loss path[10]Evidence dated Jun 22, 2026 | Why it mattersUnit 42's research describes how cloud naming and lifecycle assumptions can create exfiltration opportunities. Preventive review must cover namespace ownership, deletion, recreation, routing, and logging. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 9 | Threat / Category npm supply chain The npm threat landscape now includes wormable, CI/CD-persistent, multi-stage campaigns[1][2]Evidence dated Source date not published | Why it mattersUnit 42's high-profile-threat lane treats package ecosystems and build pipelines as an active enterprise attack surface. Package trust, maintainer identity, lockfiles, build isolation, and secret protection are central controls. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 10 | Threat / Category Claim-state discipline Unit 42 demonstrates how to separate observed behavior from underground attribution[7]Evidence dated Jun 26, 2026 | Why it mattersThe credential-attack brief records the actor's claimed responsibility and sale offer while stating it was not validated. IntelliOS should preserve that exact boundary in alerts and linked actor cards. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 11 | Threat / Category Observation begins Personalized recruiter impersonation turned public executive profiles into a payment-fraud lure[20]Evidence dated Apr 2026 | Why it mattersUnit 42 tracked attackers posing as Palo Alto Networks recruiters from August 2025, using scraped LinkedIn details and a fabricated résumé-scoring problem to pressure senior professionals into paying for supposed remediation. Verification must move to an official careers portal or company domain. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 12 | Threat / Category Multi-wave espionage begins Boggy Serpens returned repeatedly through trusted relationships instead of relying on one durable foothold[19]Evidence dated Mar 2026 | Why it mattersUnit 42 documented four waves against one maritime-sector organization from August 2025 through February 2026. Social engineering, relationship compromise and evolving AI-assisted implants make repeated access attempts the story—not one payload. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 13 | Threat / Category Developer supply chain Shai-Hulud made stolen maintainer identity a wormable distribution mechanism[16]Evidence dated Sep 2025 | Why it mattersThe September campaign stole npm, GitHub and cloud credentials, republished compromised packages and propagated without direct action against each downstream organization. Developer workstations and CI/CD secrets became part of the enterprise perimeter. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 14 | Threat / Category Muddled Libra intrusion Muddled Libra built a rogue VM inside vSphere and used the victim's own cloud and certificate trust[17]Evidence dated Feb 2026 | Why it mattersDuring a September incident, Unit 42 observed reconnaissance, tooling, persistence, stolen certificates, domain-controller interaction and Snowflake access from a rogue virtual machine. Defenders need inventory and behavioral controls for management-plane assets, not just guest workloads. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 15 | Threat / Category Shai-Hulud second wave Shai-Hulud 2.0 expanded to more than 25,000 malicious repositories and added destructive fallback[16]Evidence dated Sep 2025 | Why it mattersUnit 42 found pre-install execution, public-repository secret exfiltration, CI/CD persistence and attempted home-directory destruction when credential theft failed. Repository scale is not a unique-enterprise victim count, but the blast-radius mechanism is clear. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 16 | Threat / Category Observed supply-chain compromise Lotus Blossom selectively hijacked Notepad++ update traffic for government and critical-infrastructure targets[18]Evidence dated Feb 2026 | Why it mattersUnit 42 reports that compromised hosting infrastructure redirected selected update requests from June through December 2025 and delivered Cobalt Strike or the Chrysalis backdoor. Valid software origin was insufficient when updater verification and hosting trust failed. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 17 | Threat / Category Observation period closes Four Boggy Serpens waves showed that failed access can lead to redesigned tradecraft, not abandonment[19]Evidence dated Mar 2026 | Why it mattersThe year-long assessment ends with a fourth wave in February 2026. Repeated social engineering and tool changes against the same strategic target argue for campaign-level memory across incidents, identities and suppliers. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Palo Alto Networks Unit 42 exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |