logo

Evil XDR: Researcher Turns Palo Alto Software Into Perfect Malware

ID: 5ac0e893-7761-5e52-97dd-aab50ad2d908

STIX ID: report--5ac0e893-7761-5e52-97dd-aab50ad2d908

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-04-19

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A SafeBreach researcher demonstrated at Black Hat Asia how Palo Alto's Cortex XDR could be abused by creating hard links to plaintext Lua rule files to bypass anti-tampering protections, load a vulnerable driver, achieve full endpoint control, and deploy a reverse shell and ransomware; Palo Alto has since fixed most issues but retained plaintext storage of the rules, and the researcher warns similar XDR products might be vulnerable to analogous techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.