
CVE-2024-3400 exploit attempts on the rise -
Coordinated attack campaign detected
The CrowdSec Network has detected a wave of exploitation attempts targeting CVE-2024-3400 in Palo Alto PAN-OS has been identified, originating from a coordinated group of IPs.
Key findings:
- The attacks are coming from previously unseen IPs.
- These IPs are linked to AS200373, an Autonomous System known for hosting #VPN providers.
- The activity has spiked suddenly, suggesting an organized effort to exploit this #vulnerability
- The scale and timing indicate that this group is working in tandem, likely testing or launching a larger attack campaign.
- The CrowdSec monitoring team has designated this group as "Sweet Orange Gyrfalcon." [2/5]