Palo Alto Network Issues Hotfixes for Zero-Day Bug in Its Firewall OS
ID: aaa25d42-0391-5fe1-b866-31eaf9dc4943
STIX ID: report--aaa25d42-0391-5fe1-b866-31eaf9dc4943
Feed Name: Dark Reading
Palo Alto Networks disclosed and released hotfixes for CVE-2024-3400, a critical command-injection vulnerability in PAN-OS GlobalProtect (10.2, 11.0, 11.1) that allows unauthenticated remote code execution. Volexity and PAN observed a targeted campaign (tracked as Operation Midnight Eclipse / UTA0218) exploiting the flaw to obtain root shells, export device configurations, and deploy a novel Python backdoor named Upstyle for lateral movement and credential/data theft; customers are urged to apply hotfixes or disable device telemetry as a temporary mitigation, and CISA added the CVE to its known exploited vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
