logo

Iran's Pioneer Kitten hits US networks via buggy Check Point, Palo Alto gear

ID: 4b63b409-4201-592d-8dea-42d23aaab267

STIX ID: report--4b63b409-4201-592d-8dea-42d23aaab267

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-08-28

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

US authorities (FBI, CISA, DC3) warn that Iranian-backed Pioneer Kitten is actively exploiting critical vulnerabilities in VPNs and firewalls (including CVE-2024-3400, CVE-2024-24919 and older Citrix/F5 flaws) to gain access to networks of schools, banks, hospitals, defense contractors and foreign targets. The group uses webshells, stolen admin credentials, created accounts, and backdoors to exfiltrate data and enable ransomware affiliates (NoEscape, Ransomhouse, ALPHV/BlackCat); defenders are advised to patch vulnerable devices, review provided IOCs, and check for cloud account misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.