logo

Anatomy of a Cyber Attack: The PAN-OS Firewall Zero-Day

ID: 25ae6d50-4340-5566-bafa-7ef0cc7778c9

STIX ID: report--25ae6d50-4340-5566-bafa-7ef0cc7778c9

Feed Name: Arctic Wolf

Threat Score
90/100

Date Published: 2024-10-07

Date Updated: 2026-07-25

Author: Arctic Wolf

...
...

On April 12, 2024, Palo Alto Networks disclosed CVE-2024-3400, a critical (CVSS 10.0) zero-day in PAN-OS GlobalProtect enabling unauthenticated remote root code execution; security researchers (Volexity) observed actor UTA0218 installing a custom Python backdoor (UPSTYLE) and using compromised firewalls to fetch additional tools. The report describes typical exploitation stages (reconnaissance, resource development, initial access via cookie content injection and path traversal, execution via cron jobs, persistence with web shells/backdoors), affected PAN-OS versions, available hotfixes, detection and mitigation guidance, and Arctic Wolf’s incident response actions during the event.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.