Security Affairs newsletter Round 468 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3400 | Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled |
Full article386 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press Newsletter
Cybercrime
AFP traps alleged RAT developer
Ransomware Group Claims Theft of Data From Chipmaker Nexperia
International investigation disrupts phishing-as-a-service platform LabHost
Threat Group FIN7 Targets the U.S. Automotive Industry
Chinese Organized Crime’s Latest U.S. Target: Gift Cards
Ransomware Victims Who Pay a Ransom Drops to Record Low
840-bed hospital in France postpones procedures after cyberattack
Malware
Unpacking the Blackjack Group’s Fuxnet Malware
LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India
Cerber Ransomware: Dissecting the three heads
Kapeka: A novel backdoor spotted in Eastern Europe
OfflRouter virus causes Ukrainian users to upload confidential documents to VirusTotal
Hacking
Hacker claims Giant Tiger data breach, leaks 2.8M records online
PuTTY vulnerability vuln-p521-bias
Palo Alto – Putting The Protecc In GlobalProtect (CVE-2024-3400)
Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials
Cisco discloses root escalation flaw with public exploit code
SteganoAmor campaign: TA558 mass-attacking companies and public institutions all around the world
CrushFTP Virtual Filesystem Escape Vulnerability in the Wild
Intelligence and Information Warfare
Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400
Misinformation And Hacktivist Campaigns Target The Philippines Amidst Rising Tensions With China
FBI says Chinese hackers preparing to attack US infrastructure
Cybersecurity
United Nations Agency Investigating Ransomware Attack Involving Data Theft
House passes bill banning Uncle Sam from snooping on citizens via data brokers
UNDP Investigates Cyber-Security Incident
ICS Network Controllers Open to Remote Exploit, No Patches Available
Advanced Cyber Threats Impact Even the Most Prepared
Government Releases Guidance on Securing Election Infrastructure
Warrantless spying powers extended to 2026 with Biden’s signature
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/162081/security/security-affairs-newsletter-round-468-by-pierluigi-paganini-international-edition.html