Anatomy of a Cyber Attack: The PAN-OS Firewall Zero-Day
ID: 25ae6d50-4340-5566-bafa-7ef0cc7778c9
STIX ID: report--25ae6d50-4340-5566-bafa-7ef0cc7778c9
Feed Name: Arctic Wolf
On April 12, 2024, Palo Alto Networks disclosed CVE-2024-3400, a critical (CVSS 10.0) zero-day in PAN-OS GlobalProtect enabling unauthenticated remote root code execution; security researchers (Volexity) observed actor UTA0218 installing a custom Python backdoor (UPSTYLE) and using compromised firewalls to fetch additional tools. The report describes typical exploitation stages (reconnaissance, resource development, initial access via cookie content injection and path traversal, execution via cron jobs, persistence with web shells/backdoors), affected PAN-OS versions, available hotfixes, detection and mitigation guidance, and Arctic Wolf’s incident response actions during the event.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
