Palo Alto Networks announced the release of patches for a significant number of vulnerabilities impacting its PAN-OS, Cortex XDR, ActiveMQ Content Pack, and Prisma Access Browser products. The most critical of these is CVE-2024-8686, a high-severity command injection flaw in PAN-OS. This vulnerability allows an authenticated admin to bypass system restrictions and execute arbitrary commands on the firewall with root privileges, presenting a serious security risk. In addition to this critical issue, Palo Alto Networks has updated its Chromium-based Prisma Access Browser to address 29 recently patched vulnerabilities in Chromium, many of which are of high severity and some of which have been actively exploited. Furthermore, the company has tackled several medium-severity vulnerabilities. One such issue in PAN-OS involves the exposure of GlobalProtect portal passwords in cleartext, potentially allowing users to uninstall or disable the GlobalProtect app beyond intended permissions. The patches also cover other notable vulnerabilities in PAN-OS, such as a flaw that allows authenticated admins to read arbitrary files from the command-line interface and another that could enable attackers to impersonate GlobalProtect users. Additionally, the ActiveMQ Content Pack now addresses cleartext credentials exposure, and a Cortex XDR Agent vulnerability affecting Windows installations has been patched to prevent unauthorized disabling of the agent by malware. Palo Alto Networks confirmed that there are no known in-the-wild exploits for these specific vulnerabilities and also assured customers that vulnerabilities found in open source software over the past decade do not affect its products.
Mozilla has released Firefox 150 to address multiple security vulnerabilities, including critical use-after-free flaws that could lead to remote code execution (RCE). The most seve...
A large-scale malware campaign has been discovered leveraging fake repositories on GitHub to distribute malicious payloads. The operation involves more than 100 fraudulent reposito...
Cybercriminal groups are increasingly exploiting French freelancer-focused fintech accounts to launder stolen funds at high speed, often transferring money within minutes before de...