logo

Zero-day exploited right now in Palo Alto Networks' GlobalProtect gateways

ID: 8be22dfd-3129-5664-83fb-c34291ca4fae

STIX ID: report--8be22dfd-3129-5664-83fb-c34291ca4fae

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-04-12

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Palo Alto Networks disclosed a critical CVE-2024-3400 command-injection zero-day in PAN-OS affecting GlobalProtect gateways (CVSS 10.0) that has been exploited in the wild by an actor tracked as UTA0218 (Operation MidnightEclipse). Volexity observed attackers obtain remote root, deploy a Python backdoor and reverse-proxy tools (e.g., GOST), establish persistence via cron jobs that wget payloads piped to bash, exfiltrate device configurations, and leverage those devices for lateral movement; fixes and mitigations were provided and a permanent patch was scheduled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.