• Awards
  • Careers
Back

What happened in the Palo Alto cyber attack?

As a leading provider of IT and cyber security solutions, we emphasise the importance of swift vulnerability management and proactive security measures. The recent exploitation of vulnerabilities in Palo Alto Networks firewalls highlights how quickly cyber criminals can take advantage of newly disclosed security flaws, gaining network access to critical systems. This underscores the urgent need for immediate action to prevent attackers from using these weaknesses to steal sensitive data and compromise business operations.

 

What happened in the Palo Alto firewall breach?

Cyber attackers have successfully exploited two critical zero-day vulnerabilities in Palo Alto Networks firewalls, impacting over 2,000 systems worldwide. These vulnerabilities – CVE-2024-0012 and CVE-2024-9474 – enable hackers to bypass authentication and escalate privileges, granting them root-level control over affected devices.

CVE-2024-0012 was first reported on November 8, with Palo Alto Networks advising customers to limit access to firewall management interfaces due to a potential remote code execution threat.

CVE-2024-9474, disclosed on November 18, has further intensified the risks by expanding the scope of potential exploitation, enabling attackers to take deeper control of compromised systems.

 

Key takeaways from the attack

Extent of the Breach: Shadowserver identified 2,700 vulnerable PAN-OS devices, with at least 2,000 already compromised, posing a severe risk to Palo Alto Networks customers.

Exploitation Methods: Attackers leverage chained exploits to bypass security measures and deploy malware, often using anonymous VPNs and even spoofing trusted internal IP addresses to evade detection.

Escalating Threat: Palo Alto Networks’ Unit 42 threat intelligence team has confirmed that exploit code is now publicly available, significantly increasing the likelihood of further attacks. The UK’s infrastructure security agency has urged organisations to patch affected systems immediately to mitigate risk.

 

The growing trend of cyber exploits and threat actors in cyber security

This incident is part of a worrying pattern of cyber attacks targeting newly discovered vulnerabilities. Organisations must prioritise continuous monitoring to detect suspicious activity, apply timely patches, and ensure critical systems remain secure and fully operational. Notable cases earlier this year include:

  • July 2024: A flaw in the Expedition tool (CVE-2024-5910) enabled attackers to reset administrator credentials on exposed servers.

  • Early 2024: A maximum severity firewall vulnerability (CVE-2024-3400) was actively exploited, compromising over 82,000 devices.

 

Mitigation and recommended actions

Palo Alto Networks urges organisations to take the following steps immediately to reduce the risk of unauthorised access to sensitive assets, including customer records, mostly business contact information, and data associated with an internal sales account:

Apply security patches:

Update to the latest PAN-OS versions that address these vulnerabilities to prevent active exploitation that could expose customer records or internal sales account data.

Restrict management access:

Limit access to the PAN-OS management interface to trusted internal IP addresses and implement strict access controls to protect systems containing mostly business contact information and other sensitive records.

Strengthen monitoring:

Implement robust security monitoring to detect unauthorised activity and potential breaches, with particular attention to access involving customer records and internal sales account activity, leveraging advanced security features for enhanced protection.

Review configuration settings:

Ensure firewall deployments adhere to best-practice deployment guidelines recommended by Palo Alto Networks to minimise exposure to attacks that could impact customer records or systems storing mostly business contact information.

 

How Zenzero can help secure your business

This attack serves as a stark reminder that cyber threats evolve rapidly, and businesses must stay ahead with proactive security measures. Data involved includes business contact data, basic case data, and information processed through third party integrations, underscoring the importance of robust controls around interconnected systems. Implementing timely patches, segmenting networks, and enforcing strict access controls are crucial to reducing risk exposure and mitigating the tactics used by threat actors.

We specialise in helping businesses safeguard their IT infrastructure against emerging threats. If your organisation relies on Palo Alto Networks affected firewalls, now is the time to assess your security posture, apply necessary patches, and restrict access to critical systems – particularly where third party integrations and access to business contact data are involved.

Contact us today to strengthen your cyber security strategy and ensure your business remains protected against evolving cyber threats.

Leave a Reply

Your email address will not be published. Required fields are marked *