Anatomy of a Cyber Attack: PAN-OS Firewall Zero-Day I Arctic Wolf
ID: 7c29aa5b-4f10-509b-bf5e-6a26a27cb96f
STIX ID: report--7c29aa5b-4f10-509b-bf5e-6a26a27cb96f
Feed Name: Arctic Wolf Blog
Arctic Wolf's report analyzes CVE-2024-3400, a PAN-OS GlobalProtect zero-day (CVSS 10.0) that enabled unauthenticated remote root code execution on PAN-OS 10.2/11.0/11.1 devices, leading to exploitation by actor UTA0218 which deployed a Python backdoor called UPSTYLE; the advisory covers attack stages (reconnaissance, initial access via SESSID cookie content injection and path traversal, execution via cron, persistence via web shell/backdoor), lists hotfixes that remediate the issue, estimates ~22,542 internet-exposed vulnerable devices, and describes Arctic Wolf's mitigation, detection, and customer response actions during the mega threat event.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
