logo

Palo Alto Expedition: From N-Day to Full Compromise

ID: 5b4d0b8d-870e-5206-a7c7-e6ab4a62ac6a

STIX ID: report--5b4d0b8d-870e-5206-a7c7-e6ab4a62ac6a

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2024-10-09

Date Updated: 2026-04-22

Author: Zach Hanley

...
...

This report details discovery and exploitation of multiple vulnerabilities in Palo Alto Networks Expedition that allow attackers to reset admin credentials, gain remote code execution via an authenticated command-injection in CronJobs.php, perform unauthenticated SQL injection to exfiltrate user and device data, and recover cleartext credentials written to logs; proofs-of-concept, post-exploitation exfiltration steps, IOCs, exposure counts (~23 internet-facing servers), and a disclosure timeline are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.