Attackers exploited CVE-2024-3400, a critical command-injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to execute code with root privileges on affected firewalls without authentication. The flaw, rated CVSS 10.0 and listed in CISA’s Known Exploited Vulnerabilities catalog, involves arbitrary file creation on vulnerable systems configured with a GlobalProtect gateway or portal. Exploitation reportedly began in March 2024, before Volexity identified zero-day activity in April. TeamT5 attributed campaigns to SLIME60, which deployed XStealer against Taiwanese and Japanese organizations, and SLIME61/UTA0218, which used UPStyle web shells, including against a Saudi Arabian manufacturer. A subsequent FortiGuard update reported Silk Typhoon exploitation in March 2024; Microsoft separately reported that actor’s targeting of the IT supply chain.
Scanning persisted well after disclosure: SANS reported increased probing in September 2025, including requests from 141.98.82.26 that tested attacker-selected file creation rather than directly executing code. Separate Recorded Future research documented RedNovember’s global targeting of government, defense, and technology organizations through exposed perimeter services, illustrating the broader edge-device threat without establishing its involvement in these GlobalProtect attacks. Organizations should upgrade affected PAN-OS deployments to patched releases and investigate potential compromise, including configuration theft, malware installation, and lateral movement. Disabling device telemetry is not an effective mitigation. FortiGuard released an IPS signature to detect and block exploitation attempts, but filtering does not replace patching or compromise assessment. Cloud NGFW, Panorama appliances, and Prisma Access are not affected by this vulnerability.

See which actors are running it and whether you're in range.
35 events from the most recent confirmed update back to the earliest known activity.
US Defense Secretary Pete Hegseth announced an expanded partnership with Panama to counter Chinese influence in the canal. Insikt Group assessed that RedNovember's subsequent Panama reconnaissance closely followed his visit.
Between April 22 and April 24, 2025, Insikt Group observed RedNovember scanning and likely reconnoitering more than 30 mostly government-related Panamanian organizations. Targets included bodies responsible for finance, foreign relations, transportation, development, and emergency services.
RedNovember conducted reconnaissance against infrastructure associated with two national scientific research organizations in Taiwan, including one focused on semiconductor-related research and development.
RedNovember's April 2025 Ivanti Connect Secure targeting included a suspected compromise of a nuclear safety-related organization funded by the South Korean government.
In March and April 2025, Insikt Group observed evidence suggesting RedNovember had likely compromised an additional intergovernmental organization based in Southeast Asia.
Following a visit by US Secretary of State Marco Rubio, President José Raúl Mulino announced that Panama would not renew its Belt and Road Initiative memorandum and would review contracts with Hutchison PPC. Insikt Group discussed these developments as context for subsequent RedNovember reconnaissance.
China conducted a surprise exercise involving approximately 90 warships and coast guard vessels and simulating attacks and blockades. Insikt Group cited the exercise as geopolitical context for contemporaneous RedNovember communications with Taiwan.
Between December 9 and December 16, 2024, Insikt Group observed communications from RedNovember server 198.98.50.218 to a Taiwanese location housing an air force base and semiconductor research and development. The server also hosted Pantegana command-and-control infrastructure.
Insikt Group first observed RedNovember targeting South Korean organizations in late August 2024.
RedNovember conducted reconnaissance against prominent aerospace and defense organizations, particularly in the United States, including suspected port scanning from 209.141.46.57. Insikt Group found no evidence of successful compromise of these targets.
FortiGuard published an Outbreak Alert and issued a Threat Signal concerning active exploitation of CVE-2024-3400.
The vulnerability record was published for CVE-2024-3400, a critical PAN-OS GlobalProtect flaw allowing unauthenticated attackers to execute arbitrary code with root privileges.
Palo Alto Networks released Threat Prevention signature 95187 to detect and block suspicious GlobalProtect session-ID patterns associated with CVE-2024-3400 exploitation. The vendor reported that the signature blocked all known and observed suspicious session-ID patterns.
Palo Alto Networks issued a security advisory for the actively exploited GlobalProtect command-injection vulnerability, which permits unauthenticated remote code execution.
Volexity identified active zero-day exploitation of the vulnerability subsequently tracked as CVE-2024-3400.
Beginning in late April 2024, SLIME60 exploited CVE-2024-3400 to deploy XStealer against Taiwanese manufacturers and Japanese education, medical, and manufacturing organizations.
Silk Typhoon exploited the GlobalProtect vulnerability in Palo Alto Networks firewalls to compromise multiple organizations in March 2024.
Since at least mid-2024, RedNovember highly likely compromised an African government's Cisco ASA appliance.
Since at least mid-2024, RedNovember highly likely compromised a Huawei router associated with a Southeast Asian government.
Since at least mid-2024, RedNovember highly likely compromised a Fortinet FortiGate appliance associated with an East Asian foreign affairs ministry.
Since at least mid-2024, RedNovember highly likely compromised a Zimbra Collaboration Suite server associated with a Southeast Asian country.
Since at least mid-2024, RedNovember highly likely compromised a 3CX web client associated with a ministry responsible for museums in a western European country.
SANS observed 141.98.82.26 probing honeypots using a path-traversal session identifier and file-existence checks associated with CVE-2024-3400. The demonstrated requests did not themselves execute code; the same source also requested /Synchronization, whose claimed association with another GlobalProtect vulnerability the author questioned.
A FortiGuard update reported that RedNovember, which overlaps with Storm-2077, targeted perimeter appliances at high-profile organizations globally.
Insikt Group identified two LESLIELOADER samples used by RedNovember to load SparkRAT, consistent with earlier reporting of the actor's Go-based loader variant.
Insikt Group observed communications suggesting a long-running RedNovember compromise of a Southeast Asian intergovernmental organization. The activity persisted at least through March 2025, but the source does not date the initial compromise or its discovery.
Insikt Group identified likely RedNovember targeting of a South American country's Outlook Web Access portals before its state visit to China. Similar activity targeted foreign affairs ministries in Southeast Asia and South America.
RedNovember conducted reconnaissance against Ivanti Connect Secure appliances at a Korean telecommunications company, a marine vessel classification organization, and a national research university.
A FortiGuard update reported that Silk Typhoon had used CVE-2024-3400 as a zero-day in March 2024 to compromise multiple organizations, adding named attribution to the exploitation history.
RedNovember compromised a Korean nonprofit in the financial services sector during the interval between late August 2024 and March 2025. The organization communicated with several of the actor's Pantegana command-and-control servers.
TeamT5 identified SLIME60 and SLIME61 as participants in CVE-2024-3400 attacks and attributed SLIME60 to China with high confidence. Its analysis supplied XStealer and UPStyle indicators and hunting guidance, although some CVE references and one IP indicator were inconsistent.
SANS documented a reported CVE-2024-3400 exploitation attempt using SESSID path traversal and a telemetry-related execution mechanism to run a Base64-encoded shell command. The payload was designed to copy running-config.xml into a web-accessible GlobalProtect directory for unauthenticated download.
Palo Alto Networks fixed CVE-2024-3400 in PAN-OS 10.2.9-h1, 11.0.4-h1, 11.1.2-h3, and later versions. The vendor also warned that disabling device telemetry was not an effective mitigation.
FortiGuard released an intrusion-prevention signature to detect and block exploitation attempts against affected edge devices.
SLIME61, also known as UTA0218, exploited CVE-2024-3400 to deploy UPStyle web shells in several attacks, including one against a Saudi Arabian manufacturing organization.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
attackerkb.com
Open sourceisc.sans.edu
Open sourcemicrosoft.com
Open sourceteamt5.org
Open sourceitscybernews.com
Open sourcepaloaltonetworks.com
Open sourceisc.sans.edu
Open sourcefortiguard.com
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.