Cortex Cloud Security Research - Palo Alto Networks

Cortex Cloud Security Research

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
We discovered a vulnerability in the Google Cloud Vertex AI software development kit (SDK) for Python, and responsibly disclosed it to Google. Before Google’s fix, the vulnerability would have allowed an attacker operating entirely from their own Google Cloud project to hijack a victim's model upload and poison it. By exploiting...

Jun 16, 2026
By Ori Hadad


Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion a...

This blog dives into the growing trend of data theft and ext...

Jun 09, 2026
By Yahav Festinger


Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

Unit 42 researchers have observed evidence of cyberattacks by the Iran-nexus advanced persistent threat...

May 22, 2026
By Unit 42


Paved With Intent: ROADtools and Nation-State Tactics in the Cloud

ROADtools is a publicly available toolkit for offensive and...

May 22, 2026
By Bill Batchelor, Eyal Rafian


Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensiv...

The offensive capabilities of large language models (LLMs) have until recently existed as...

Apr 23, 2026
By Yahav Festinger, Chen Doytshman


Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asi...

We uncovered a High severity security vulnerability CVE-2026-0628 in Google's implementation of the new Gemini feature in Chrome. This vulnerability a...

Mar 26, 2026
By Doel Santos, Hiroaki Hara


Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentic...

Passwordless authentication is often presented as the end of account takeover. But to unde...

Mar 23, 2026
By Arie Olshtein


Boggy Serpens Threat Assessment

We have been tracking ongoing cyberespionage campaigns by the threat group Boggy Serpens, also known as MuddyWater. Attr...

Mar 16, 2026
By Unit 42


A Peek Into Muddled Libra’s Operational Playbook

Feb 10, 2026
By Justin De Luna, Noah Rincon, Cuong Dinh


Novel Technique to Detect Cloud Threat Actor Operations

Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. The...

Feb 06, 2026
By Nathaniel Quist


The Shadow Campaigns: Uncovering Global Espionage

This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. We refer to the group’s activity as the Shadow Campaigns. W...

Feb 05, 2026
By Unit 42


DNS OverDoS: Are Private Endpoints Too Private?

We discovered an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks. In this article, we explore how both intentio...

Jan 20, 2026
By Golan Myers


From Linear to Complex: An Upgrade in RansomHouse Encryption

Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.

Dec 17, 2025
By Anmol Maurya, Jingwen Shi


Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities Wit...

In recent months, we have been analyzing the activity of an advanced persistent threat (APT) known for its espionage activities against Arabic-speakin...

Dec 11, 2025
By Unit 42


Cloud Discovery With AzureHound

AzureHound is a data collection tool intended for penetration testing that is part of the BloodHound suite. Threat actors misuse this tool to enumerat...

Oct 24, 2025
By Margaret Kelley, Bill Batchelor, Eyal Rafian


Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign

Unit 42 stopped monitoring this threat and updating the brief on Sept. 18, 2025. Please refer to the Microsoft SharePoin...

Oct 22, 2025
By Stav Setty, Shachar Roitman


The Golden Scale: Bling Libra and the Evolving Extortion Economy

Oct 10, 2025
By Matt Brady