Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-05 · 02:16 UTC
articleTotal: 1184 reports

Filtered Reports

12 / 12 results
Active filter:tag: #palo-alto-networks✕ clear
Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprintinghighperson_alertThreat Actor
person_alertThreat Actor

Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting

Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…

Palo Alto Networks11 Aug · 17:36 UTC
Chrome Password Manager passkey bypass allows malware to hijack accountshighbug_reportVulnerability
bug_reportVulnerability

Chrome Password Manager passkey bypass allows malware to hijack accounts

Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.

Google3 Aug · 14:24 UTC
Passkey auth bypass via User Verified flag validation gap in relying partieshighbug_reportVulnerability
bug_reportVulnerability

Passkey auth bypass via User Verified flag validation gap in relying parties

Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.

Palo Alto Networks3 Aug · 08:00 UTC
knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaignhighperson_alertThreat Actor
person_alertThreat Actor

knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaign

knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher.

Palo Alto Networks31 Jul · 09:21 UTC
Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Accesshighperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access

Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.

CVE-2026-025721 Jul · 12:04 UTC
Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerabilitycriticalperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability

Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…

Palo Alto Networks21 Jul · 08:12 UTC
CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian governmenthighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government

CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.

Palo Alto Networks26 Jun · 14:21 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025715 Jun · 04:17 UTC
Active exploitation of PAN-OS CVE-2026-0257 reported by Unit 42highbug_reportVulnerability
bug_reportVulnerability

Active exploitation of PAN-OS CVE-2026-0257 reported by Unit 42

Palo Alto Networks PAN-OS (specific affected versions not provided in available data)

CVE-2026-02575 Jun · 12:05 UTC
PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit

Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.

CVE-2026-025730 May · 16:02 UTC
Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wildhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild

Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.

CVE-2026-025730 May · 04:41 UTC
Critical PAN-OS vulnerabilities enable auth bypass and code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical PAN-OS vulnerabilities enable auth bypass and code execution

Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.

Palo Alto Networks18 May · 12:43 UTC