"Palo Alto Networks Addresses Zero-Day Exploits in Firewalls"

TL;DR Summary
Palo Alto Networks has released hotfixes for a zero-day vulnerability (CVE-2024-3400) actively exploited since March 26th to backdoor PAN-OS firewalls, affecting versions 10.2, 11.0, and 11.1. Threat actors can exploit it remotely to gain root code execution, prompting the company to issue hotfixes and advise disabling device telemetry on vulnerable devices. Security firm Volexity confirmed active exploitation and linked it to state-sponsored threat actors, while CISA has ordered federal agencies to apply threat mitigation or disable telemetry within a week.
Topics:business#cybersecurity#exploitedvulnerability#firewallsecurity#paloaltonetworks#threatmitigation#zerodayvulnerability
- Palo Alto Networks fixes zero-day exploited to backdoor firewalls BleepingComputer
- Palo Alto Networks Warns of Exploited Firewall Vulnerability SecurityWeek
- “Highly capable” hackers root corporate networks by exploiting firewall 0-day Ars Technica
- Zero-day exploited right now in Palo Alto Networks' GlobalProtect gateways The Register
- Palo Alto Networks Releases Urgent Fixes for Exploited PAN-OS Vulnerability The Hacker News
Reading Insights
Total Reads
0
Unique Readers
1
Time Saved
2 min
vs 2 min read
Condensed
79%
382 → 80 words
Want the full story? Read the original article
Read on BleepingComputer