Palo Alto Networks Releases Urgent Fixes for Exploited PAN-OS Vulnerability
ID: d989fc28-6dbf-52dc-96bb-e7748ecc2498
STIX ID: report--d989fc28-6dbf-52dc-96bb-e7748ecc2498
Feed Name: The Hacker News
Threat Score
Palo Alto Networks released hotfixes for CVE-2024-3400 (CVSS 10.0), a command-injection flaw in PAN-OS GlobalProtect actively exploited in the wild to execute arbitrary root commands; observed activity attributed to UTA0218 / Operation MidnightEclipse includes deployment of the UPSTYLE Python backdoor, reverse shells, configuration exfiltration, log removal, and use of the GOST tunneling tool, with patches, hunting commands, and public PoCs available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
