Another CVE (PAN-OS Zero Day)
ID: d936dad9-22bb-51e9-a366-97fa11708969
STIX ID: report--d936dad9-22bb-51e9-a366-97fa11708969
Feed Name: Zscaler Security Research Blog
This report details CVE-2024-3400, a critical PAN-OS command-injection zero-day (CVSS 10.0) being actively exploited to enable unauthenticated root code execution on Palo Alto firewalls. It describes an observed attack chain—initial exploitation, persistence via Cron and tools such as a UPSTYLE Python backdoor and GOST reverse proxy, lateral movement using SMB/WinRM, theft of AD backup/NTDS.DIT and DPAPI/browser secrets, and exfiltration to an externally accessible web directory—and provides vendor mitigation guidance and affected PAN-OS versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
