Tag: Palo Alto

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login
News

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

A proof-of-concept (PoC) exploit for a high-severity security vulnerability affecting GlobalProtect Gateway and Portal has been provided by Palo Alto Networks. A denial-of-service (DoS) situation affecting GlobalProtect PAN-OS software has been identified as the vulnerability, tagged as CVE-2026-0227 (CVSS score: 7.7), which results from an incorrect check for exceptional conditions (CWE-754). In an advisory published on Wednesday, Palo Alto Networks stated that a flaw in the PAN-OS software allows an unauthorized attacker to launch a denial-of-service (DoS) attack on the firewall. The firewall goes into maintenance mode after multiple efforts to cause this problem. The following versions are impacted by the problem, which was found and reported by an anonymous outside researcher...
Massive brute force attack uses 2.8 million IPs to target VPN devices
News

Massive brute force attack uses 2.8 million IPs to target VPN devices

Almost 2.8 million IP addresses are being used in a massive brute force password attack that aims to guess the login credentials for a variety of networking devices, including those made by Palo Alto Networks, Ivanti, and SonicWall. When threat actors try to repeatedly log into a device or account using a large number of usernames and passwords until they find the right combination, this is known as a brute force attack. Once the threat actors obtain the right credentials, they can use them to access a network or take control of a device. The Shadowserver Foundation, a threat monitoring platform, reports that a brute force attack has been going on since last month, using around 2.8 million source IP addresses every day to carry out these attacks read more about Massive brute force a...
Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign
News

Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

It is expected that a campaign exploiting the recently revealed security weaknesses that have been actively exploited in the field infected up to 2,000 Palo Alto Networks devices. The Shadowserver Foundation published figures showing that the U.S. (554) and India (461), followed by Thailand (80), Mexico (48), Indonesia (43), Turkey (41), the U.K. (39), Peru (36), and South Africa (35), have reported the most infections. Censys reported earlier this week that it had discovered 13,324 next-generation firewall (NGFW) administration interfaces that were openly accessible, with 34% of these exposures being in the United States. It's crucial to remember that not every one of these exposed hosts is inherently at risk read more about Over 2000 Palo Alto Networks Devices Hacked in Ongoing At...
CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches
News

CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security issue affecting Fortinet devices to its Known Exploited Vulnerabilities (KEV) database on Wednesday. The vulnerability affects FortiOS, FortiPAM, FortiProxy, and FortiWeb and is listed as CVE-2024-23113 (CVSS score: 9.8). It is related to incidents of remote code execution. Fortinet stated in an advisory for the vulnerability back in February 2024 that a remote, unauthenticated attacker may be able to execute arbitrary code or commands through the exploitation of an externally-controlled format string vulnerability [CWE-134] in the FortiOS fgfmd daemon. As usual, there are few specifics in the warning about how the vulnerability is being used in th...