Zero-day exploited right now in Palo Alto Networks' GlobalProtect gateways
ID: 8be22dfd-3129-5664-83fb-c34291ca4fae
STIX ID: report--8be22dfd-3129-5664-83fb-c34291ca4fae
Feed Name: The Register (Security)
Palo Alto Networks disclosed a critical CVE-2024-3400 command-injection zero-day in PAN-OS affecting GlobalProtect gateways (CVSS 10.0) that has been exploited in the wild by an actor tracked as UTA0218 (Operation MidnightEclipse). Volexity observed attackers obtain remote root, deploy a Python backdoor and reverse-proxy tools (e.g., GOST), establish persistence via cron jobs that wget payloads piped to bash, exfiltrate device configurations, and leverage those devices for lateral movement; fixes and mitigations were provided and a permanent patch was scheduled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
