logo

Wiz observes exploitation in the wild of PAN-OS vulnerabilities

ID: 191d2890-435a-525e-a3cd-df6ff3d03d1f

STIX ID: report--191d2890-435a-525e-a3cd-df6ff3d03d1f

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2024-11-22

Date Updated: 2026-05-01

...
...

Wiz reports active exploitation of PAN-OS vulnerabilities CVE-2024-0012 (authentication bypass) and CVE-2024-9474 (privilege escalation) which, when chained, allow unauthenticated RCE against PAN-OS management interfaces; exploitation increased after a public proof-of-concept and at least ~2,000 instances have been reported compromised. Observed post-exploitation artifacts include simple PHP web shells, Sliver implants (C2 77.221.158.154 / censysinspect.com), XMRig miners, and Linux implants attributed to DaggerFly; the report lists affected PAN-OS version ranges, IOCs (file hashes, paths), and recommends patching, restricting management access, and using Wiz scanning/detection tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.