Palo Alto Networks says it has observed exploitation of two zero-days in its PAN-OS firewall OS; researchers say hackers have compromised 2,000+ firewalls
Malicious hackers have compromised potentially thousands of organizations by exploiting two new zero-day vulnerabilities found …
TechCrunchCarly Page
Context & Ripple Effects
This is the second PAN-OS exploitation warning in the related coverage within the same year: Palo Alto Networks had already alerted customers to a zero-day under active exploitation in GlobalProtect. The new report broadens the concern from a single product component to two flaws in the firewall operating system.
The scale also fits a recurring pattern in network infrastructure: Cisco’s IOS XE incident showed how actively exploited edge-device flaws can expose large installed bases before remediation takes hold at-risk IOS XE devices.
First-order effects
Organizations running affected PAN-OS firewalls face an immediate exposure-assessment and incident-response task after researchers identified more than 2,000 compromised devices.
Palo Alto Networks must support customers confronting active exploitation across its firewall platform, not merely a theoretical vulnerability disclosure.
Second-order effects
Security teams are likely to prioritize visibility and containment around internet-facing firewall management and remote-access infrastructure, alongside normal patching workflows.
The incident raises the operational cost of relying on perimeter appliances as trusted control points: a compromised firewall can become a high-value foothold into the organization it is meant to protect.
Third-order effects
If repeated exploitation of firewall and VPN platforms persists, enterprise security programs will increasingly treat network-edge devices as continuously monitored endpoints rather than set-and-forget infrastructure.
The broader market shift is toward resilience measures—asset inventory, rapid exposure reduction, and compromise detection—that matter even when zero-days arrive before a vendor fix.
The trend: Repeated zero-day attacks on internet-facing security appliances are pushing perimeter defense from a product-patching problem toward a continuous exposure-management and detection discipline.
Heads-up! Thanks to collaboration with the Saudi NCA — we are now scanning & reporting Palo Alto Networks devices COMPROMISED as a result of a CVE-2024-0012/CVE-2024-9474 campaign. — Found ~2000 instances compromised on 2024-11-20: — dashboard.shadowserver.org/statistics/ …
Favorite quote from WatchTowr's blog about PAN-OS vuln: — > I guess auto_prepend_file actually has legitimate use besides writing PHP exploits. — labs.watchtowr.com/pots-and- pan...
Palo Alto published an authentication bypass vulnerability scoring severity 9.3. There is no patch available, only some urgent mitigating actions. Get those mgmt interfaces offline and put them private. Found some belgian exposed PA's and reported some. security.paloaltonetwor…
Reading the awesome WatchTowr writeup of CVE-2024-0012 and CVE-2024-9474, the Palo Alto RCE/privesc one-two punch. Great work here as always. — labs.watchtowr.com/pots-and- pan... A few things stand out:
We've been observing ongoing exploitation of the recent PAN-OS RCE vuln chain (CVE-2024-0012 + CVE-2024-9474) over the past few days and we're sharing our research findings and a few IOCs: https://www.wiz.io/...
We now have a @metasploit exploit module in the pull queue for the PAN-OS management interface unauthenticated RCE exploit chain (CVE-2024-0012 + CVE-2024-9474), based upon the technical analysis published today by @watchtowrcyber. https://github.com/... [image]
🚨 ONGOING: Threat actors are actively exploiting the PAN-OS RCE vulnerability chain (CVE-2024-0012 + CVE-2024-9474) to deploy malware. After observing ongoing exploitation of these vulnerabilities over the past few days, we're sharing our findings. Details and IOCs 👇
This threat brief discusses observed exploitation activity of authentication bypass vulnerability CVE-2024-0012, which affects specific versions of PAN-OS software. We cover current mitigations and more: https://unit42.paloaltonetworks.com/ ... [image]
Hackers have compromised potentially thousands of organizations by exploiting two new zero-day vulnerabilities in software made by cybersecurity giant Palo Alto Networks https://techcrunch.com/...