CVE-2026-0257 around Palo Alto Networks GlobalProtect has turned into a live-fire incident, not a theoretical risk. After CISA issued warnings, Rapid7 reports they’ve observed real exploitation inside customer environments—with multiple waves of attacks. Rapid7’s timeline is especially worrying: early activity appeared May 17—just 3 days after Palo Alto Networks published an advisory on May 14. The key issue isn’t just the CVSS rating. Attackers target VPN edge deployments, where they can bypass identity checks. Once that foothold works, outcomes can escalate fast—from unauthorized access to deeper internal network compromise. Rapid7 says their MDR team began incident response around 18:00 UTC on the 18th and spotted suspicious VPN authentication attempts. The log pattern included “non-human” credentials. Investigation pointed to a shared hosting provider (Vultr), and analysis suggested firewall cloud identity services (CAS) were disabled while GlobalProtect’s authentication override cookies were enabled—consistent with cookie-based exploitation. A second wave hit May 21, allegedly from another host (Dromatics Systems), but with highly similar MAC indicators. Action: immediately review GlobalProtect configuration, cookie override behavior, and anomalous auth + VPN connection logs; pair with MDR/logs for targeted hunting and hardening. #CyberSecurity #PaloAlto #GlobalProtect #Vulnerability #ThreatIntel #MDR
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论