Over 2,000 Palo Alto Networks firewalls have been compromised in a widespread attack using two recently patched vulnerabilities (CVE-2024-0012 and CVE-2024-9474), according to Shadowserver Foundation’s internet scanning.
Palo Alto Networks security researchers reported on Wednesday that they detected a “limited set of exploitation activity” involving two vulnerabilities in PAN-OS, the operating system for their next-generation firewalls. These vulnerabilities are classified as zero-days because patches could not be released before they were exploited.
Sygnia's recent report highlights the changing strategies of ransomware groups targeting VMware ESXi appliances. These attackers exploit vital virtual infrastructure...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released 6 advisories for Industrial Control Systems (ICS), highlighting vulnerabilities in various...
The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory...
Cisco has released a security advisory concerning a critical privilege escalation vulnerability (CVE-2025-20156) in its Meeting Management software. With a...
CVE-2024-0012 is a vulnerability in Palo Alto Networks PAN-OS that lets unauthenticated attackers with network access to the management interface gain administrator privileges. This could enable them to perform administrative tasks, alter configurations, or exploit other vulnerabilities, such as CVE-2024-9474.
Palo Alto Networks’ Unit 42 research team has named the ongoing attack campaign “Operation Lunar Peek.” Since early November, attackers have been seen installing malware and executing commands on compromised firewalls, suggesting the presence of a public exploit chain.
The Shadowserver Foundation reports that hackers have compromised over 2,000 Palo Alto Networks firewalls by exploiting two recently patched vulnerabilities. Most affected devices are in the United States, followed by India, with additional breaches in the UK, Australia, and China.
Organizations should review the security advisories for guidance on remediation.