❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

Separating that network

3 August 2026 at 03:42
ON SECURITY By Susan Bradley OpenAI’s recent attack on another company’s cloud instances reminds me that sometimes we forget the basics. As we understand the situation at the moment, OpenAI’s test platform was meant to be isolated and not connected to the Internet. But because it needed to download certain items, it was given read-only […]

How Windows Firewall works

6 July 2026 at 03:44
NETWORKING By Mary Branscombe Windows tries to keep your PC safe online by not allowing incoming network connections unless the software you’re using asks for them. Here’s how it figures that out, and how you can fine-tune it. In the real world, a firewall is a physical barrier meant to stop a fire β€” or […]

Using the firewall in your router to secure your SOHO network

6 July 2026 at 03:43
NETWORKING By Simon Bisson Small Office/Home Office (SOHO) routers are more secure than you think β€” although they could do with a little help from their friends. Way back when we used dial-up to connect to the Internet, software firewalls such as ZoneAlarm were all we needed to protect our PCs β€” because slow-speed connections […]

Attackers are exploiting Palo Alto Networks defect that initially flew under the radar

1 June 2026 at 18:29

Researchers and threat hunters are scrambling to respond to an actively exploited authentication-bypass vulnerability affecting Palo Alto Networks customers’ firewalls.Β 

The company initially tagged CVE-2026-0257 with a medium-severity rating when it disclosed the defect May 13, but quickly reassessed it as critical after Rapid7 observed and confirmed active exploitation in the wild. The Cybersecurity and Infrastructure Security Agency followed suit, and added the vulnerability to its known exploited vulnerabilities catalog Friday.

The escalated threat posed by the defect, which allows remote attackers to bypass security restrictions and establish a VPN connection to an affected firewall, showcases how quickly a seemingly mild vulnerability can turn into an urgent warning.Β 

β€œPalo Alto Networks is actively monitoring limited exploitation attempts targeting CVE-2026-0257 on unpatched PAN-OS devices where mitigations have not been applied,” a company spokesperson said in a statement. The company on Friday urged all customers to immediately apply the patch or follow its recommended steps for mitigation.Β 

The vendor and Rapid7, which first observed exploitation May 17 in a customer environment, declined to say how many organizations are impacted thus far. Yet, Douglas McKee, director of vulnerability intelligence at Rapid7, warned: β€œWe’ve continued to see new victims roll in, including a couple of customers hit within just an hour of each other during a second wave of activity” on May 21.Β 

Jake Knott, security researcher at watchTowr, told CyberScoop the vulnerability and resulting exploits follows a recurring trend wherein attackers target exposed network edge devices and rapidly identify, develop and weaponize exploits for initial access.Β 

β€œThis is yet another authentication bypass on a device whose sole job is to guard the front door to an organization’s network,” he said. β€œWhat stands out is how simple it is β€” an attacker can forge a valid authentication cookie using nothing more than the appliance’s publicly available TLS certificate. The entire exploit is a single HTTP request.”

The vulnerability has a few requisites that limit exposure, specifically posing risk to some Palo Alto Networks customers running GlobalProtect portal or gateway configured to enable authentication override cookies.Β 

β€œThe cookie encryption and decryption certificate must be reused with another feature, which potentially exposes the public key for that certificate,” said Caitlin Condon, vice president of security research at VulnCheck.

β€œIt’s difficult to say how many deployments meet those criteria for exploitability, but Palo Alto Networks firewalls have a very large footprint, which means even uncommon configurations can present significant attack surface area,” she added.

Rapid7 said the same attacker or group is likely responsible for both waves of exploitation last month, but in many cases attackers are not establishing a full VPN connection or moving to other parts of the impacted network.Β 

The attackers are β€œhighly opportunistic and clearly monitor the security research community,” McKee said. β€œAttackers are purposefully weaponizing medium-severity vulnerabilities, which are typically lower priority or blind spots for organizations.”

Multiple threat clusters are swarming to the opportunity and quickly adapting to published research.Β  Researchers have not attributed the malicious activity to any specific threat groups.Β 

β€œTheir exact origins and long-term objectives remain unclear, as they currently seem focused purely on opportunistic initial access rather than targeted, long-term espionage,” McKee said.Β 

Palo Alto Networks said it discovered the vulnerability internally through its use of frontier AI tools. Yet, within days of its public disclosure, initial assessments were proven inadequate.

β€œThis is a pattern we continue to see β€” the urgency only arrives after exploitation is underway,” Knott said. β€œOrganizations that wait for confirmation of active exploitation before patching will consistently find themselves reacting too late.”

The post Attackers are exploiting Palo Alto Networks defect that initially flew under the radar appeared first on CyberScoop.

Bypassing WAFs Using Oversized Requests

By: BHIS
15 October 2025 at 10:00

Many web application firewalls (WAFs) can be bypassed by simply sending large amounts of extra data in the request body along with your payload. Most WAFs will only process requests up to a certain size limit. How the WAF is configured to handle these large requests determines exploitability, but some common WAFs will allow it by default.

The post Bypassing WAFs Using Oversized Requests appeared first on Black Hills Information Security, Inc..

The New Security Fundamentals – Kill Your AV

By: BHIS
3 November 2015 at 16:35

John StrandΒ // AV is Dead Long Live Whitelisting. We have been discovering more and more of our tests bypass AV controls with ease.Β Β We have yet to see any iteration or […]

The post The New Security Fundamentals – Kill Your AV appeared first on Black Hills Information Security, Inc..

❌
❌