logo

Anatomy of a Cyber Attack: The PAN-OS Firewall Zero-Day

ID: 10dc6527-b88a-526c-9055-668712d07c9d

STIX ID: report--10dc6527-b88a-526c-9055-668712d07c9d

Feed Name: Arctic Wolf

Threat Score
90/100

Date Published: 2024-10-07

Date Updated: 2026-07-25

Author: Arctic Wolf

...
...

Arctic Wolf analyzes CVE-2024-3400, a critical (CVSS 10.0) PAN-OS GlobalProtect zero-day actively exploited in the wild to achieve unauthenticated root remote code execution; the adversary UTA0218 used content-injection via cookies and path traversal to write files, schedule cron jobs, and install a Python backdoor (UPSTYLE) to gain persistence and stage further intrusions, while Palo Alto released hotfixes for affected PAN-OS versions and Arctic Wolf executed a coordinated mega-event response to detect and block exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.