Tag: palo alto networks
89 articles

Microsoft Teams Targeted in Voice Phishing Campaigns
Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

AI Reshapes Cyber Threat Landscape, Favoring Attackers
The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

Kimwolf Botnet Evolves to Evade DDoS Detection
The Kimwolf botnet has levelled up its game with a new upgrade, v7, which uses HTTP/2 floods to mimic real browser traffic, making it super tricky to detect as a DDoS attack. This sneaky move lets the botnet build complete browser fingerprints, blurring the line between legit and malicious traffic.

China Probes Palo Alto Networks Product Security
China is investigating the security of Palo Alto Networks' products, sparking a mysterious probe that's left many questions unanswered. The inquiry, reported by The Register, puts the spotlight on Palo Alto Networks and its offerings.

XCSSET Malware Targets macOS Devs Through Compromised Xcode Projects
macOS developers, beware: XCSSET malware is lurking in compromised Xcode projects, infecting unsuspecting victims through a sneaky four-stage infection chain that can deploy 17 distinct modules. This latest variant has been rewritten to dig deep into your workflow and browser, putting your entire development ecosystem at risk.

Malware Exploits Direct IP Connections to Evade DNS-Based Defenses
Nearly half of malware samples with command-and-control activity connect directly to IP addresses, dodging DNS-based defenses and highlighting a significant blind spot in traditional security measures. This alarming trend was uncovered in an analysis of over 4 million dynamic reports, revealing that 45.32% of malicious code uses direct-to-IP connections to evade detection.

AI-Powered Vulnerability Discovery Surges, Threatens Patch Window
In a staggering two-month sprint, Palo Alto Networks' NOVA uncovered 14,090 confirmed vulnerabilities in just 3,915 open-source software projects - a remarkable demonstration of AI-powered vulnerability discovery's rapid impact. This autonomous pipeline is revolutionizing the way we identify and tackle software vulnerabilities.

Malware Exploits Google Passkey Sync Flaws
Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

AI-Powered Attacks Target Vulnerable Servers With Autonomous Exploits
Meet the AI-powered attackers who just took autonomous exploitation to the next level - and here's how researchers uncovered their clever tactics. A China-based threat actor's accidental leak exposed a functional, end-to-end AI-driven attack workflow.

Chinese Hackers Leverage DeepSeek for Autonomous Exploits
Meet the sneaky Chinese hackers who've been using an AI-powered tool called DeepSeek to launch autonomous cyber attacks on over 460 targets - and get a glimpse into their clever tactics. With just a single Telegram instruction, DeepSeek can infiltrate and exploit systems all on its own.

Qilin Ransomware Exploits Palo Alto Networks Flaw for Initial Access
In a recent wave of attacks, hackers exploited a high-severity flaw in Palo Alto Networks' PAN-OS software to gain initial access for Qilin ransomware attacks. This vulnerability, known as CVE-2026-0257, allowed attackers to bypass authentication and establish VPN sessions without valid credentials.

Qilin Ransomware Gang Exploits Palo Alto VPN Bug in Ongoing Attacks
The Qilin ransomware gang is actively exploiting a critical vulnerability in Palo Alto Networks' VPN software, CVE-2026-0257, to breach security and launch attacks, despite a patch being released on May 13. This alarming development follows reports of multiple intrusions by Qilin in June, highlighting the urgent need for updates.

Private 5G Networks Expose Government to Hidden Security Risks
Government agencies and military organizations risk exposing themselves to hidden security threats if they don't adopt a zero-trust approach to their private 5G networks, leaving them vulnerable to potentially devastating attacks. Without proper security measures in place, adversaries could gain unrestricted access to sensitive information and wreak havoc.

Startup Sues Palo Alto Networks Unit Over AI-Generated Espionage Claims
When a cybersecurity report wrongly labeled MeetingTV a part of a Chinese espionage operation, its CEO knew it was a death sentence - and now the video conferencing startup is fighting back with a lawsuit against Palo Alto Networks and Koi Security. MeetingTV alleges the report, generated by AI, was reckless and falsely accused it of criminal conduct.

AI Models Expose Millions to Phantom Squatting Phishing Threat
Millions are now at risk of falling prey to a new, rapidly evolving phishing threat called phantom squatting, where attackers exploit AI-generated links to create malicious websites that can evade detection. By registering domains invented by large language models, hackers can create seemingly trustworthy sites that are actually designed to steal sensitive information or spread malware.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors
Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

MacOS ClickFix Attack Exploits Terminal Commands to Spread Infostealer
Beware of a sneaky new attack on macOS, known as ClickFix, that tricks you into pasting a Terminal command, allowing hackers to silently download and launch info-stealing malware on your device. This cleverly crafted scam starts with a fake CAPTCHA page, convincing victims to unwittingly give attackers a backdoor to their sensitive data.

Cloud Providers' Global Namespace Flaw Enables Bucket Hijacking
A newly discovered flaw in cloud providers' global namespace has been exploited in a simple yet powerful bucket hijacking technique, allowing attackers to redirect sensitive data streams into their own accounts. This alarming vulnerability affects multiple services across major cloud providers.

Palo Alto Networks Warns of Active Exploitation of GlobalProtect VPN Flaw
Palo Alto Networks has warned of active exploitation of a critical GlobalProtect VPN flaw, CVE-2026-0257, which allows attackers to bypass security controls and set up unauthorized VPN connections. The company first observed exploitation attempts on May 17, 2026.

AI Skills Marketplace Exposes Security Gaps
A recent audit of OpenClaw's AI skills marketplace uncovered a staggering 250,706 behavioral deviations in 49,943 agent "skills", revealing a significant gap between what AI skills claim to do and what they actually do. This alarming mismatch highlights the urgent need for robust security measures, such as Palo Alto Networks' Unit 42's Behavioral Integrity Verification (BIV) solution.

Attackers Target Cloud Logging Services for Defense Evasion and Continuous Visibility
Cloud logging services, like AWS CloudTrail and Google Cloud Logging, are a treasure trove of insights into your cloud environment - but they're also a prime target for attackers looking to erase their tracks or gain continuous visibility into your operations. By manipulating these services, adversaries can create persistent blind spots that leave you vulnerable.

Palo Alto Networks Warns of Active PAN-OS Vulnerability Exploitation
Palo Alto Networks has sounded the alarm on a critical PAN-OS vulnerability, CVE-2026-0257, that's being actively exploited by threat actors to bypass authentication and gain unauthorized access to VPN connections. This security gap could allow attackers to circumvent controls and initiate their own VPN sessions, putting your network at risk.

Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users
macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.

Malvertising Campaign Targets macOS with FlutterShell Backdoor
Google swiftly suspended advertiser accounts linked to a massive malvertising campaign that spread a new macOS backdoor, known as FlutterShell, after researchers sounded the alarm. The culprits, tracked by Palo Alto Networks as CL-CRI-1089, used hundreds of verified Google ads and a web of shell companies to deceive ad networks.