Threat Vector by Palo Alto Networks

Inside 750 Breaches with Unit 42

Feb 19, 2026
Steve Elovitz, incident response leader for Unit 42 with 15+ years at Mandiant, PwC, and Booz Allen, breaks down what 750+ breaches reveal. He discusses shrinking detection windows and autonomous containment. Identity as the top attack surface and overprivileged SaaS integrations get focus. High-ROI defensive priorities like segmentation, identity hardening, and visibility are highlighted.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

How Unit 42 Handles The First Call

  • Unit 42 fields 24/7 incident calls and immediately builds chronology and situational awareness with customers.
  • Steve Elovitz says his team pairs a caller-facing lead with a second person who runs threat intelligence lookups in real time.
INSIGHT

AI Scales And Speeds Attacks

  • AI is accelerating attackers by automating reconnaissance, social engineering, and post-exploitation steps.
  • Elovitz notes AI lowered attackers' costs and increased scale, letting less skilled actors achieve advanced results quickly.
ANECDOTE

Malware Outsourced Decisions To An LLM

  • Unit 42 observed malware (Lame Hug) that reached out to Hugging Face to outsource post-exploitation decisions.
  • That outsourcing let the actor automate next-step commands and move faster across many targets.
Get the Snipd Podcast app to discover more snips from this episode
Get the app