CrowdSec<p>CVE-2024-3400 exploit attempts on the rise - <br>Coordinated attack campaign detected</p><p>The CrowdSec Network has detected a wave of exploitation attempts targeting CVE-2024-3400 in Palo Alto PAN-OS has been identified, originating from a coordinated group of IPs.</p><p>Key findings:<br>- The attacks are coming from previously unseen IPs.<br>- These IPs are linked to AS200373, an Autonomous System known for hosting <a href="https://infosec.exchange/tags/VPN" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VPN</span></a> providers.<br>- The activity has spiked suddenly, suggesting an organized effort to exploit this <a href="https://infosec.exchange/tags/vulnerability" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vulnerability</span></a> <br>- The scale and timing indicate that this group is working in tandem, likely testing or launching a larger attack campaign.<br>- The CrowdSec monitoring team has designated this group as "Sweet Orange Gyrfalcon." 🧵 [2/5]</p>