Evil XDR: Researcher Turns Palo Alto Software Into Perfect Malware
ID: 5ac0e893-7761-5e52-97dd-aab50ad2d908
STIX ID: report--5ac0e893-7761-5e52-97dd-aab50ad2d908
Feed Name: Dark Reading
Threat Score
A SafeBreach researcher demonstrated at Black Hat Asia how Palo Alto's Cortex XDR could be abused by creating hard links to plaintext Lua rule files to bypass anti-tampering protections, load a vulnerable driver, achieve full endpoint control, and deploy a reverse shell and ransomware; Palo Alto has since fixed most issues but retained plaintext storage of the rules, and the researcher warns similar XDR products might be vulnerable to analogous techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
