Palo Alto Networks Discloses More Details on Critical PAN-OS Flaw Under Attack
ID: 87856503-a875-5c40-8741-79f04d2708a9
STIX ID: report--87856503-a875-5c40-8741-79f04d2708a9
Feed Name: The Hacker News
Palo Alto Networks disclosed CVE-2024-3400 (CVSS 10.0), an intricate chain of two GlobalProtect bugs in PAN-OS that can be combined to achieve unauthenticated remote shell command execution; the flaw is being actively exploited by UTA0218 (tracked as Operation MidnightEclipse) using a cron-based implant that retrieves and executes attacker-controlled payloads. A proof-of-concept is public, CISA added the issue to its Known Exploited Vulnerabilities list, Shadowserver estimates ~22,542 internet-exposed vulnerable devices, and Palo Alto has released hotfixes across multiple PAN-OS maintenance releases—organizations should apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
