Palo Alto Networks has warned its users about 34 vulnerabilities in their products and released four security advisories. They haven’t found any attacks yet, but it’s important for users to update their systems quickly.
Certain Palo Alto products, specifically PAN-OS and GlobalProtect App, are affected by vulnerabilities. Some of these security gaps stem from third-party software, underscoring the interconnected nature of today’s digital ecosystem.
By infosecbulletin
/ Wednesday , February 5 2025
AMD announced patches on Monday for a microprocessor vulnerability that risks the loss of Secure Encrypted Virtualization (SEV) protection, potentially...
Read More
By infosecbulletin
/ Wednesday , February 5 2025
Hackers are using HTTP client tools for advanced account takeover attacks on Microsoft 365. Seventy-eight percent of Microsoft 365 tenants...
Read More
By infosecbulletin
/ Wednesday , February 5 2025
Google has released patches for 47 security flaws in Android, including one that is actively being exploited. CVE-2024-53104 (CVSS score: 7.8)...
Read More
By infosecbulletin
/ Tuesday , February 4 2025
Microsoft has released patches for two critical security flaws in Azure AI Face Service and Microsoft Account that could allow...
Read More
By infosecbulletin
/ Tuesday , February 4 2025
Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
By infosecbulletin
/ Tuesday , February 4 2025
In 2024, 768 vulnerabilities with CVE identifiers were reported as exploited in the wild, a 20% increase from 639 in...
Read More
By infosecbulletin
/ Monday , February 3 2025
A recent report from Cofense Intelligence highlights a concerning trend: threat actors are increasingly misusing .gov top-level domains (TLDs) to...
Read More
By infosecbulletin
/ Sunday , February 2 2025
The cybersecurity seminar "RedSentry presents: Hacked 101," organized by RedSentry with the University of Information Technology and Sciences (UITS) as...
Read More
By infosecbulletin
/ Sunday , February 2 2025
Researchers at the University of California, Berkeley, claims they’ve managed to reproduce the core technology behind DeepSeek’s at a total...
Read More
By infosecbulletin
/ Sunday , February 2 2025
This week, multiple research teams showcased jailbreaks for popular AI models, including OpenAI's ChatGPT, DeepSeek, and Alibaba's Qwen. After its...
Read More
Prisma Access Browser Update:
The Prisma Access Browser, based on Chromium, has been updated to version 127.100.2858.4. This update includes fixes for 31 vulnerabilities from four “Chromium” updates between July 16 and August 6.
Of particular concern are CVE-2024-7532 and CVE-2024-6990, labeled as “Critical” by Google. Though Palo Alto assigns these a slightly lower CVSSv4.0 base score of 8.6, they still carry a “High” severity rating, emphasizing the need for swift action.
Cortex XSOAR Patch:
Cortex XSOAR version 1.12.33 fixed a command injection vulnerability (CVE-2024-5914) in the CommonScripts Pack. This flaw has a CVSS score of 7.0 and could allow an attacker to execute arbitrary commands without authentication, potentially compromising the system.
Additional Vulnerabilities Addressed:
The advisories also tackled:
CVE-2024-5916 (CVSS 6):
A fixed vulnerability in PAN-OS and Cloud NGFW versions that unintentionally exposed sensitive data
CVE-2024-5915 (CVSS 5.2):
The GlobalProtect app on Windows has a vulnerability that allows local users to run programs with higher privileges. The issue will be fixed in future app updates.
Call to Action:
Palo Alto Networks advises users to update their systems with the latest patches to protect against potential cyber threats. It’s important to stay proactive in cybersecurity to ensure strong defense.