Security News

Palo Alto Networks tags new firewall bug as exploited in attacks
2025-02-19 15:38

Palo Alto Networks warns that hackers are actively exploiting a critical authentication bypass flaw (CVE-2025-0108) in PAN-OS firewalls, chaining it with two other vulnerabilities to breach...

Attackers are chaining flaws to breach Palo Alto Networks firewalls
2025-02-19 08:50

Exploitation attempts targeting CVE-2025-0108, a recently disclosed authentication bypass vulnerability affecting the management web interface of Palo Alto Networks’ firewalls, are ramping up....

Palo Alto firewalls under attack as miscreants chain flaws for root access
2025-02-19 00:15

If you want to avoid urgent patches, stop exposing management consoles to the public internet A flaw patched last week by Palo Alto Networks is now under active attack and, when chained with two...

SonicWall firewalls now under attack: Patch ASAP or risk intrusion via your SSL VPN
2025-02-14 22:53

Roses are red, violets are blue, CVE-2024-53704 is perfect for a ransomware crew Miscreants are actively abusing a high-severity authentication bypass bug in unpatched internet-facing SonicWall...

SonicWall firewall bug leveraged in attacks after PoC exploit release
2025-02-14 18:13

Attackers are now targeting an authentication bypass vulnerability affecting SonicWall firewalls shortly after the release of proof-of-concept (PoC) exploit code. [...]

Mysterious Palo Alto firewall reboots? You're not alone
2025-02-13 07:21

Limited-edition hotfix to get wider release before end of month Administrators of Palo Alto Networks' firewalls have complained the equipment falls over unexpectedly, and while a fix has bee...

Fortinet discloses second firewall auth bypass patched in January
2025-02-11 18:56

Fortinet has disclosed a second authentication bypass vulnerability that was fixed as part of a January 2025 update for FortiOS and FortiProxy devices. [...]

Fortinet warns of new zero-day exploited to hijack firewalls
2025-02-11 18:56

Fortinet warned today that attackers are exploiting another authentication bypass zero-day bug in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

SonicWall firewall exploit lets hackers hijack VPN sessions, patch now
2025-02-11 15:56

Security researchers at Bishop Fox have published complete exploitation details for the CVE-2024-53704 vulnerability that allows bypassing the authentication mechanism in certain versions of the...

Over 12,000 KerioControl firewalls exposed to exploited RCE flaw
2025-02-10 23:58

Over twelve thousand GFI KerioControl firewall instances are exposed to a critical remote code execution vulnerability tracked as CVE-2024-52875. [...]