Skip to content
You can now search across every topic, entity and event.What's new
Unit 42
OrganisationUS

Unit 42

Palo Alto Networks' threat-intelligence and incident-response division; named CL-STA-1132.

Unit 42, Palo Alto Networks' threat-intelligence arm, published attribution in May 2026 confirming that state-sponsored cluster CL-STA-1132 had exploited PAN-OS since 16 April, its own vendor's product.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Can Unit 42 be objective when the exploited vulnerability is in Palo Alto's own product?

Timeline for Unit 42

#12 29 Jul

Mentioned in: A fifth filing, materiality still open

Cybersecurity: Threats and Defences
#5 21 May

Mentioned in: AI orchestration flaw joins CISA's KEV

Cybersecurity: Threats and Defences
#4 7 May

Mentioned in: West Pharma SEC 8-K on ransomware halt

Cybersecurity: Threats and Defences
#3 16 Apr

Confirmed CL-STA-1132 exploitation and documented post-exploitation tradecraft

Cybersecurity: Threats and Defences: CL-STA-1132 exploited PAN-OS since 16 April, log destruction confirmed
View full timeline →

Background

Unit 42 is the threat-intelligence and incident-response Arm of Palo Alto Networks, one of the world's largest cybersecurity vendors. In May 2026, Unit 42 published attribution confirming that state-sponsored cluster CL-STA-1132 had been actively exploiting CVE-2026-0300 in PAN-OS since 16 April 2026, detailing tradecraft including nginx shellcode injection, Active Directory enumeration via firewall service accounts, and systematic log destruction .

Unit 42 conducts original threat research, responds to major incidents for enterprise clients, and publishes threat-actor naming conventions used across the industry: a CL- prefix for unattributed clusters, APT prefixes for attributed groups. Its annual Unit 42 Incident Response Report tracks ransomware, business email compromise and nation-state trends.

The CL-STA-1132 publication placed Unit 42 at the centre of the PAN-OS zero-day response, a position carrying reputational sensitivity since the vulnerability affects Palo Alto's own product. Independent corroboration from other vendors has strengthened the attribution, and Unit 42's visibility into exploitation comes partly from telemetry on PAN-OS devices deployed at scale globally.

Common Questions
What is Unit 42 and who funds it?
Unit 42 is the threat-intelligence and incident-response division of Palo Alto Networks, funded by the commercial cybersecurity vendor. It conducts research and responds to enterprise incidents.
How did Unit 42 discover the CL-STA-1132 PAN-OS attacks?
Unit 42 confirmed exploitation of CVE-2026-0300 in PAN-OS captive portal by CL-STA-1132 since 16 April 2026, using telemetry from PAN-OS devices and Incident Response engagements to document the tradecraft.Source: Unit 42
Is Unit 42 independent from Palo Alto Networks?
Unit 42 is a division of Palo Alto Networks, not an independent body. Its research on PAN-OS vulnerabilities therefore carries a commercial sensitivity, though its findings are typically corroborated by other vendors.
Source Material