Risky Bulletin Newsletter
April 15, 2024
Risky Biz News: Palo Alto Networks scrambles to push zero-day patch
Presented by

News Editor
Palo Alto Networks has scrambled over the weekend to release a software patch for its firewall devices. The patch is intended to fix a zero-day (CVE-2024-3400) in the GlobalProtect VPN feature of PAN-OS, the firmware that runs on Palo Alto's firewalls.
Security firm Volexity discovered the attacks, which the company attributed to a group it tracks as UTA0218. Palo Alto tracks this as Operation MidnightEclipse.
Volexity described the group as a state-backed threat actor but did not link the group to any country.