The recently discovered zero-day vulnerability in Palo Alto Networks PAN-OS software has been used by threat actors since March 26, 2024, or over three weeks prior to its discovery yesterday.
Under the moniker Operation MidnightEclipse, the network security company’s Unit 42 division is monitoring the activity and crediting it to the efforts of a lone threat actor with an unidentified origin.
This command injection vulnerability, listed as CVE-2024-3400 (CVSS score: 10.0), allows unauthenticated attackers to run arbitrary code on the firewall with root privileges.
It is important to note that this problem only affects firewall installations running PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 with GlobalProtect gateway and device telemetry enabled read more Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
