Close Menu
    What's Hot

    How Quebec Left the Church and Became the World Leader in Assisted Dying

    Bus crash in Ethiopian mountains kills at least 31 | Transport News

    London Man Suspected in 2017 Shoving of a Woman Into Bus Path Is Arrested

    Facebook X (Twitter) Instagram
    Trending
    • How Quebec Left the Church and Became the World Leader in Assisted Dying
    • Bus crash in Ethiopian mountains kills at least 31 | Transport News
    • London Man Suspected in 2017 Shoving of a Woman Into Bus Path Is Arrested
    • How Does One Brain Speak Two Languages?
    • UK unveils sweeping social media ban for users under 16
    • Will SpaceX Fortunes Trickle Down to This Texas Town?
    • Jerash Holdings (US), Inc. (JRSH) Q4 2026 Earnings Call Transcript
    • Sabri Lamouchi expecting sack by Tunisia before next World Cup game – sources
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

    adminBy adminJune 15, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 15, 2026Vulnerability / VPN Security

    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

    Palo Alto Networks has revealed that it has observed “active exploitation” of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.

    The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.

    According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections.

    The vulnerability has been exploited in the wild in limited attacks, with initial activity observed on May 17, 2026. It’s currently unknown who is behind the exploitation efforts.

    “No post-access behavior or lateral movement has been identified as of this time,” Palo Alto Networks said. “Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events.”

    Cybersecurity

    The company has also released indicators of compromise (IoCs) associated with the activity –

    • IP addresses –

      • 23.128.228[.]6
      • 104.207.144[.]154
      • 146.19.216[.]119
      • 146.19.216[.]120
      • 146.19.216[.]125
      • 179.43.172[.]213
      • 185.195.232[.]139
      • 198.12.106[.]60
      • 202.144.192[.]47
    • Host Names and MAC Addresses –

      • aa:bb:cc:dd:ee:ff
      • 00:11:22:33:44:55
      • WINDOWS-LAPTOP-001
      • DESKTOP-GP01
      • GP-CLIENT

    Palo Alto Networks is also urging customers to search GlobalProtect logs for successful gateway-connected events that match the following hard-coded client configuration values from a proof-of-concept (PoC) exploit –

    • endpoint_os_version : Microsoft Windows 10 Pro 64-bit
    • source_user_info.domain : empty

    Late last month, the U.S. Cybersecurity and Infrastructure Security Agency (CSIA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to mitigate the flaw by June 1, 2026.

    active Alto Exploitation flaw GlobalProtect Palo PANOS VPN warns
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleIs There Such a Thing as Timeless Jeans?
    Next Article Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses
    admin
    • Website

    Related Posts

    LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

    June 15, 2026

    Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

    June 15, 2026

    The Onboarding Password Mistake That Creates Unnecessary Risk

    June 15, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    How Quebec Left the Church and Became the World Leader in Assisted Dying

    Bus crash in Ethiopian mountains kills at least 31 | Transport News

    London Man Suspected in 2017 Shoving of a Woman Into Bus Path Is Arrested

    How Does One Brain Speak Two Languages?

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by