unit42.paloaltonetworks.com 17 Sept 2026, 22:00 UTC

Attackers Are Crossing Eight Attack Surfaces in One Campaign, Unit 42 Finds

Attackers Are Crossing Eight Attack Surfaces in One Campaign, Unit 42 Finds
CyberSIXT Evidence Panel Source marked as original reporting

UNIT 42 says attackers are increasingly moving between cloud, endpoint, network, identity and software-as-a-service (SaaS) environments after gaining an initial foothold. Its 2026 Global Incident Response Report found that 43% of attacks involved activity across at least four attack surfaces, with some spanning as many as eight. The company argues that disconnected security tools can leave gaps, allowing related activity to appear as separate incidents rather than part of one attack.

The report describes investigations beginning with apparently isolated events, such as an endpoint alert, an unusual cloud resource, or an application requesting elevated permissions. Attackers may then change SaaS permissions, provision or reconfigure cloud resources, stage sensitive data for exfiltration and establish unusual network connections.

Unit 42 says AI-driven correlation can connect these signals, helping analysts reconstruct how an intruder entered, moved through systems, accessed data and pursued an objective. It recommends unified incident storylines, cross-domain threat hunting and continuous refinement of detection rules, automation and response playbooks.

Unit 42 also describes applying this approach through its Cortex SecOps platform, Managed Detection and Response, Managed Threat Hunting and Managed XSIAM services. The company says its analysts use behavioural analytics, threat intelligence and frontline investigation experience to validate attack paths, investigate activity that has not generated alerts and optimise integrations, detections, correlation rules, workflows and automated responses.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline