# Cortex Cloud Security Research

**Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE**  
We discovered a vulnerability in the Google Cloud Vertex AI software development kit (SDK) for Python, and responsibly disclosed it to Google. Before Google’s fix, the vulnerability would have allowed an attacker operating entirely from their own Google Cloud project to hijack a victim's model upload and poison it. By exploiting...

Jun 16, 2026  
By [Ori Hadad](https://unit42.paloaltonetworks.com/author/ori-hadad/ "Posts by Ori Hadad")

---

## [Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion a...](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/)
This blog dives into the growing trend of data theft and ext...

Jun 09, 2026  
By [Yahav Festinger](https://unit42.paloaltonetworks.com/author/yahav-festinger/ "Posts by Yahav Festinger")

---

## [Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/)
Unit 42 researchers have observed evidence of cyberattacks by the Iran-nexus advanced persistent threat...

May 22, 2026  
By [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/ "Posts by Unit 42")

---

## [Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/)
ROADtools is a publicly available toolkit for offensive and...

May 22, 2026  
By [Bill Batchelor](https://unit42.paloaltonetworks.com/author/cap-bill-batchelor/ "Posts by Bill Batchelor"), [Eyal Rafian](https://unit42.paloaltonetworks.com/author/cap-eyal-rafian/ "Posts by Eyal Rafian")

---

## [Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensiv...](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/)
The offensive capabilities of large language models (LLMs) have until recently existed as...

Apr 23, 2026  
By [Yahav Festinger](https://unit42.paloaltonetworks.com/author/yahav-festinger/ "Posts by Yahav Festinger"), [Chen Doytshman](https://unit42.paloaltonetworks.com/author/chen-doytshman/ "Posts by Chen Doytshman")

---

## [Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asi...](https://unit42.paloaltonetworks.com/espionage-campaigns-target-se-asian-government-org/)
We uncovered a High severity security vulnerability CVE-2026-0628 in Google's implementation of the new Gemini feature in Chrome. This vulnerability a...

Mar 26, 2026  
By [Doel Santos](https://unit42.paloaltonetworks.com/author/doel-santos/ "Posts by Doel Santos"), [Hiroaki Hara](https://unit42.paloaltonetworks.com/author/cap-hiroaki-hara/ "Posts by Hiroaki Hara")

---

## [Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentic...](https://unit42.paloaltonetworks.com/passwordless-authentication/)
Passwordless authentication is often presented as the end of account takeover. But to unde...

Mar 23, 2026  
By [Arie Olshtein](https://unit42.paloaltonetworks.com/author/arie-olshtein/ "Posts by Arie Olshtein")

---

## [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)
We have been tracking ongoing cyberespionage campaigns by the threat group Boggy Serpens, also known as MuddyWater. Attr...

Mar 16, 2026  
By [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/ "Posts by Unit 42")

---

## [A Peek Into Muddled Libra’s Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

Feb 10, 2026  
By [Justin De Luna](https://unit42.paloaltonetworks.com/author/cap-justin-de-luna/ "Posts by Justin De Luna"), [Noah Rincon](https://unit42.paloaltonetworks.com/author/cap-noah-rincon/ "Posts by Noah Rincon"), [Cuong Dinh](https://unit42.paloaltonetworks.com/author/cap-cuong-dinh/ "Posts by Cuong Dinh")

---

## [Novel Technique to Detect Cloud Threat Actor Operations](https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging/)
Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. The...

Feb 06, 2026  
By [Nathaniel Quist](https://unit42.paloaltonetworks.com/author/nathaniel-quist/ "Posts by Nathaniel Quist")

---

## [The Shadow Campaigns: Uncovering Global Espionage](https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/)
This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. We refer to the group’s activity as the Shadow Campaigns. W...

Feb 05, 2026  
By [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/ "Posts by Unit 42")

---

## [DNS OverDoS: Are Private Endpoints Too Private?](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/)
We discovered an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks. In this article, we explore how both intentio...

Jan 20, 2026  
By [Golan Myers](https://unit42.paloaltonetworks.com/author/cap-golan-myers/ "Posts by Golan Myers")

---

## [From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)
Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.

Dec 17, 2025  
By [Anmol Maurya](https://unit42.paloaltonetworks.com/author/cap-anmol-maurya/ "Posts by Anmol Maurya"), [Jingwen Shi](https://unit42.paloaltonetworks.com/author/cap-jingwen-shi/ "Posts by Jingwen Shi")

---

## [Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities Wit...](https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/)
In recent months, we have been analyzing the activity of an advanced persistent threat (APT) known for its espionage activities against Arabic-speakin...

Dec 11, 2025  
By [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/ "Posts by Unit 42")

---

## [Cloud Discovery With AzureHound](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/)
AzureHound is a data collection tool intended for penetration testing that is part of the BloodHound suite. Threat actors misuse this tool to enumerat...

Oct 24, 2025  
By [Margaret Kelley](https://unit42.paloaltonetworks.com/author/cap-margaret-kelley/ "Posts by Margaret Kelley"), [Bill Batchelor](https://unit42.paloaltonetworks.com/author/cap-bill-batchelor/ "Posts by Bill Batchelor"), [Eyal Rafian](https://unit42.paloaltonetworks.com/author/cap-eyal-rafian/ "Posts by Eyal Rafian")

---

## [Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign](https://unit42.paloaltonetworks.com/cloud-based-gift-card-fraud-campaign/)
Unit 42 stopped monitoring this threat and updating the brief on Sept. 18, 2025. Please refer to the Microsoft SharePoin...

Oct 22, 2025  
By [Stav Setty](https://unit42.paloaltonetworks.com/author/cap-stav-setty/ "Posts by Stav Setty"), [Shachar Roitman](https://unit42.paloaltonetworks.com/author/cap-shachar-roitman/ "Posts by Shachar Roitman")

---

## [The Golden Scale: Bling Libra and the Evolving Extortion Economy](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/)

Oct 10, 2025  
By [Matt Brady](https://unit42.paloaltonetworks.com/author/cap-matt-brady/ "Posts by Matt Brady")
