<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Palo Alto Networks Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Palo Alto Networks.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Palo Alto Networks to Acquire Observability Platform Provider Embrace</title><link>https://securityweek.com/palo-alto-networks-to-acquire-observability-platform-provider-embrace</link><guid isPermaLink="false">cst-3016</guid><description>Palo Alto Networks announced an acquisition of Embrace, an observability platform provider, extending its expansion into monitoring and observability tools beyond traditional security offerings. This follows the company's January acquisition of Chronosphere, signaling a strategic shift toward broader infrastructure visibility capabilities.</description><pubDate>Wed, 22 Jul 2026 14:58:53 GMT</pubDate></item><item><title>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-202-02</link><guid isPermaLink="false">cst-2933</guid><description>Palo Alto Networks published security advisories for multiple vulnerabilities in PAN-OS software affecting Siemens RUGGEDCOM APE1808 devices with embedded Virtual NGFW across all versions. The three disclosed vulnerabilities include a cross-site scripting (XSS) flaw, a privilege escalation issue for authenticated administrators with CLI access, and a command injection vulnerability allowing arbitrary root-level commands. Siemens customers are directed to implement workarounds from Palo Alto Networks upstream advisories and contact support for patching.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Critical Palo Alto VPN bug now exploited by Qilin ransomware gang</title><link>https://bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks</link><guid isPermaLink="false">cst-2883</guid><description>The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect to gain initial access to target networks. Arctic Wolf researchers documented this threat actor leveraging the flaw as part of their attack chain.</description><pubDate>Tue, 21 Jul 2026 10:12:24 GMT</pubDate></item><item><title>Lumen expands managed detection and response with Cortex XSIAM integration</title><link>https://helpnetsecurity.com/2026/07/13/lumen-defender-amdr</link><guid isPermaLink="false">cst-2405</guid><description>Lumen Technologies announced Lumen Defender Advanced Managed Detection and Response for Palo Alto Networks Cortex XSIAM, combining its managed detection and response capabilities with threat intelligence from Black Lotus Labs and Cortex XSIAM's AI-driven security operations platform. The service aims to help enterprises modernize security operations and manage the accelerating threat landscape.</description><pubDate>Mon, 13 Jul 2026 13:17:25 GMT</pubDate></item><item><title>Palo Alto Networks Patches 13 Vulnerabilities</title><link>https://securityweek.com/palo-alto-networks-patches-13-vulnerabilities</link><guid isPermaLink="false">cst-2254</guid><description>The company patched 13 vulnerabilities in PAN-OS software, including buffer overflow, denial of service, command injection, server-side request forgery (SSRF), and authentication bypass issues.</description><pubDate>Thu, 09 Jul 2026 13:49:42 GMT</pubDate></item><item><title>FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations</title><link>https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html</link><guid isPermaLink="false">cst-38</guid><description>Security researchers have linked the FortiBleed credential theft campaign to infrastructure associated with both INC and Lynx ransomware operations, with evidence showing operators managing negotiation panels for both groups. The stolen FortiGate credentials appear to be harvested for follow-on ransomware deployment rather than standalone credential trafficking.</description><pubDate>Thu, 02 Jul 2026 08:00:49 GMT</pubDate></item><item><title>Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware</title><link>https://thehackernews.com/2026/07/phantom-squatting-uses-ai-hallucinated.html</link><guid isPermaLink="false">cst-52</guid><description>Attackers are purchasing domains that large language models (LLMs) hallucinate or fabricate, then hosting phishing and malware on those nonexistent addresses to capture traffic directed by AI tools. Security researchers at Palo Alto Networks' Unit 42 have documented this technique, termed phantom squatting, actively occurring in real-world attacks.</description><pubDate>Wed, 01 Jul 2026 07:20:51 GMT</pubDate></item><item><title>Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257</title><link>https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257</link><guid isPermaLink="false">cst-344</guid><description>Unit 42 has published a threat brief documenting active exploitation of PAN-OS vulnerability CVE-2026-0257, including indicators of activity and mitigation measures. The brief provides technical details for security teams tracking this threat.</description><pubDate>Tue, 09 Jun 2026 14:05:42 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild</title><link>https://wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300</link><guid isPermaLink="false">cst-1290</guid><description>A critical buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks PAN-OS User-ID Authentication Portal enables unauthenticated remote code execution with root privileges and is being exploited in active attacks.</description><pubDate>Wed, 06 May 2026 12:33:26 GMT</pubDate></item><item><title>Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways</title><link>https://greynoise.io/blog/credential-based-campaign-cisco-palo-alto-networks-vpn-gateways</link><guid isPermaLink="false">cst-1868</guid><description>GreyNoise has identified a coordinated, automated campaign attempting to compromise enterprise VPN gateways through credential-based attacks targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears to be systematically probing authentication infrastructure across multiple organizations.</description><pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate></item><item><title>A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect</title><link>https://greynoise.io/blog/hidden-pattern-credential-based-attacks-palo-alto-sonicwall</link><guid isPermaLink="false">cst-1871</guid><description>GreyNoise observed over 7,000 IP addresses attempting to log into Palo Alto GlobalProtect, with attack signatures matching earlier SonicWall API scanning and previous Palo Alto campaigns. The incidents indicate a sustained pattern of credential-based attacks spanning several months against these security vendors' products.</description><pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High</title><link>https://greynoise.io/blog/palo-alto-scanning-surges-90-day-high</link><guid isPermaLink="false">cst-1873</guid><description>GreyNoise detected a 40-fold surge in scanning activity targeting Palo Alto Networks GlobalProtect portals starting on November 14, 2025, within a 24-hour period, reaching the highest level observed in the previous 90 days. This escalation indicates increased malicious reconnaissance efforts against the internet-facing authentication gateway. The activity suggests either exploitation attempts following a newly disclosed vulnerability or an organized campaign targeting known Palo Alto deployments.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Surge in Palo Alto Networks Scanner Activity Indicates Possible Upcoming Threats</title><link>https://greynoise.io/blog/surge-palo-alto-networks-scanner-activity</link><guid isPermaLink="false">cst-1909</guid><description>Over the past 30 days, approximately 24,000 unique IP addresses have attempted to access Palo Alto Networks portals in a coordinated pattern. The probing activity suggests reconnaissance for exposed or vulnerable systems that could lead to targeted attacks.</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Critical vulnerabilities in Palo Alto Expedition: everything you need to know</title><link>https://wiz.io/blog/palo-alto-networks-expedition-critical-vulnerabilities-advisory</link><guid isPermaLink="false">cst-1542</guid><description>Palo Alto Networks' Expedition tool contains five critical vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467) that require urgent patching. These flaws expose organizations using the migration and assessment platform to significant risk.</description><pubDate>Thu, 10 Oct 2024 17:45:48 GMT</pubDate></item></channel></rss>