State-sponsored hackers likely behind zero-day attacks on Palo Alto firewalls
ID: 71c65b40-dcc6-5f07-84cb-b186de23f714
STIX ID: report--71c65b40-dcc6-5f07-84cb-b186de23f714
Feed Name: Help Net Security
Palo Alto Networks Unit 42 reports active exploitation of a PAN-OS zero-day (CVE-2026-0300) in User-ID Authentication Portal services that enables unauthenticated RCE on PA- and VM-Series firewalls; attackers conducted a stealthy multi-stage intrusion (RCE, cleanup, privilege escalation, AD enumeration) and deployed tunnelling tools (EarthWorm, ReverseSocks5). The activity is likely state-sponsored, limited exploitation has been observed, and Palo Alto has issued mitigations, attack signatures and IOCs while working on a patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
