Thousands of Palo Alto Networks firewalls have been compromised by two recently fixed vulnerabilities.
Two vulnerabilities allowed hackers to install malware on Palo Alto Networks’ firewalls and gain access to the devices. The intruders were able to remotely control the devices and install cryptocurrency miners and other malware.
2,000 devices
As The Register knows, hackers hijacked about 2,000 devices until Palo Alto Networks released a patch for the vulnerabilities one day. After the patches became available last week, the number of compromised devices fell to around 800.
“Palo Alto Networks has observed threat activity. “It exploits this vulnerability for a limited number of management web interfaces that are exposed to Internet traffic from outside the network,” the vendor’s security advisories for the two vulnerabilities read.
Palo Alto Networks released patches on Tuesday. It remains unclear who is behind the attacks and how many devices were actually compromised. Two additional critical vulnerabilities were recently discovered in Palo Alto Networks’ Expedition migration tool.