HomeSecurityOver 2,000 Palo Alto firewalls compromised via zero-day

Over 2,000 Palo Alto firewalls compromised via zero-day

Hackers have already compromised thousands of Palo Alto Networks firewalls in attacks that exploit two recently patched zero-day flaws.

See also: Palo Alto Networks patches two zero-day firewall vulnerabilities

Palo Alto firewalls

Palo Alto's two security flaws are an authentication bypass (CVE-2024-0012) in the PAN-OS management web interface that remote attackers can exploit to gain administrator privileges, and a PAN-OS privilege escalation (CVE-2024-9474) that helps them execute commands on firewalls with root privileges.

While CVE-2024-9474 was disclosed this Monday, the company first warned customers on November 8 to restrict access to next-generation firewalls due to a potential RCE flaw (which was flagged last Friday as CVE-2024-0012).

Palo Alto Networks is still investigating ongoing attacks that link the two flaws to target "a limited number of device management web interfaces" and has already observed malicious actors distributing malware and executing commands on compromised firewalls, warning that a chain exploit.

See also: Palo Alto Networks warns of critical zero-day vulnerability

Although the company says the attacks only affect a "very small number of PAN-OS firewalls," threat monitoring platform Shadowserver reported Wednesday that it is monitoring more than 2,700 vulnerable PAN-OS devices.

Over 2,000 Palo Alto firewalls compromised via zero-day

Shadowserver is also tracking the number of compromised Palo Alto Networks firewalls and said that about 2,000 have been compromised since the start of this ongoing campaign.

CISA has added both vulnerabilities to its List of Known Exploitable Vulnerabilities and is now requiring federal agencies to patch their firewalls within three weeks by December 9th.

See also: Microsoft fixes Windows zero-day that allows attacks in Ukraine

Zero-day vulnerabilities are one of the most serious threats to the security of computer systems. These vulnerabilities arise when a security hole is discovered in a software or system without prior awareness by its developers or manufacturers. Because these vulnerabilities have not yet been patched, they are exploited by malicious actors to carry out attacks, often with devastating consequences. It is critical for technology companies to develop rapid response processes to discover and remediate these holes in order to protect data and users from potential security incidents.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS