logo

State-sponsored hackers likely behind zero-day attacks on Palo Alto firewalls

ID: 71c65b40-dcc6-5f07-84cb-b186de23f714

STIX ID: report--71c65b40-dcc6-5f07-84cb-b186de23f714

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

Author: Zeljka Zorz

...
...

Palo Alto Networks Unit 42 reports active exploitation of a PAN-OS zero-day (CVE-2026-0300) in User-ID Authentication Portal services that enables unauthenticated RCE on PA- and VM-Series firewalls; attackers conducted a stealthy multi-stage intrusion (RCE, cleanup, privilege escalation, AD enumeration) and deployed tunnelling tools (EarthWorm, ReverseSocks5). The activity is likely state-sponsored, limited exploitation has been observed, and Palo Alto has issued mitigations, attack signatures and IOCs while working on a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.