Tag Archives: Shodan

June "In the Trend of VM" (#28): Linux kernel, Microsoft Defender, and Palo Alto Networks device vulnerabilities

June In the Trend of VM (#28): Linux kernel, Microsoft Defender, and Palo Alto Networks device vulnerabilities

June "In the Trend of VM" (#28): Linux kernel, Microsoft Defender, and Palo Alto Networks device vulnerabilities. Presenting the traditional monthly roundup of trending vulnerabilities according to Positive Technologies. In the previous May edition, we covered four vulnerabilities. This time, there are also four vulnerabilities associated with five CVE identifiers.

🗞 Post on Habr (rus)
🗒 Digest on the PT website (rus)

🔻 EoP - Linux Kernel "Dirty Frag" (CVE-2026-43284, CVE-2026-43500). A chain of vulnerabilities with a public exploit to obtain root access. There are signs of in-the-wild exploitation.

🔻 EoP - Linux Kernel "Fragnesia" (CVE-2026-46300). Another vulnerability for gaining root access with a public exploit.

🔻 EoP - Microsoft Defender "RedSun" (CVE-2026-41091). A privilege escalation vulnerability leading to SYSTEM-level access, with a public exploit available and indications of in-the-wild exploitation. Pay special attention to Windows server and desktop environments where Microsoft Defender is enabled but there is no Internet access for regular updates.

🔻 RCE - PAN-OS (CVE-2026-0300). An unauthenticated RCE with root privileges affecting PA-Series and VM-Series firewalls. A public exploit exists, and there are indications of in-the-wild exploitation.

🟥 The full list of trending vulnerabilities is available on the portal

About Remote Code Execution - PAN-OS (CVE-2026-0300) vulnerability

About Remote Code Execution - PAN-OS (CVE-2026-0300) vulnerability

About Remote Code Execution - PAN-OS (CVE-2026-0300) vulnerability. PAN-OS is an operating system for Palo Alto Networks firewalls and security platforms. User-ID™ Authentication Portal (also known as Captive Portal) is a non-default PAN-OS feature used to map IP addresses to usernames. By exploiting a buffer overflow vulnerability (CWE-787), an unauthenticated remote attacker can send specially crafted packets to a device with the Authentication Portal enabled, achieving arbitrary code execution with root privileges on the affected device. No authentication or user interaction is required. If the vulnerability is successfully exploited, the attacker gains full control over network traffic: they can intercept, modify, or block connections, access sensitive data, bypass security policies, hide traces of compromise, install backdoors, and use the device as a foothold for attacks on internal infrastructure.

⚙️ The vendor security advisory was published on May 6. PA-Series and VM-Series firewalls are affected. Prisma Access, Cloud NGFW, and Panorama appliances are not impacted by this vulnerability. Security updates for affected devices became available on May 13. As a workaround, the vendor recommended restricting User-ID™ Authentication Portal access to only trusted internal zones or disabling the User-ID™ Authentication Portal entirely if it is not required.

👾 On the same day, May 6, researchers from Palo Alto Networks Unit 42 published a report on active exploitation of the vulnerability in the wild. Post-exploitation activity includes deployment of publicly available tunneling tools (EarthWorm, ReverseSocks5), Active Directory enumeration using credentials likely obtained from the firewall, and systematic destruction of logs and other evidence of compromise. On the same day, the vulnerability was added to the CISA KEV catalog.

🛠 A public exploit was also published on GitHub on May 6.

🌐 PAN-OS is among the most widely deployed enterprise firewall operating systems in the world. As of June 5, Shodan identifies approximately 135,755 internet-facing PAN-OS instances, representing a significant attack surface.

About Authentication Bypass - GNU Inetutils (CVE-2026-24061) vulnerability

About Authentication Bypass - GNU Inetutils (CVE-2026-24061) vulnerability

About Authentication Bypass - GNU Inetutils (CVE-2026-24061) vulnerability. GNU Inetutils is a collection of common network programs, including, among other things, a Telnet server (telnetd). A vulnerability in GNU Inetutils telnetd allows a remote attacker to obtain a root shell on the host without any credentials by sending a crafted USER environment variable containing the value "-f root".

⚙️ A patch fixing the vulnerability was released on January 20. Versions 1.9.3–2.7 are vulnerable; the issue went undisclosed for 10+ years. 🤷‍♂️

🛠 A detailed write-up and exploit were published by SafeBreach on January 22.

👾 Exploitation in the wild has been observed by GreyNoise since January 21.

🌐 Shodan estimates ~212,396 Telnet servers online in total. How many of them use GNU Inetutils and are vulnerable is still unclear. CyberOK discovered around 500 potentially vulnerable Telnet servers in the Russian Internet segment.

На русском

Yesterday Qualys introduced CyberSecurity Asset Management 3.0

Yesterday Qualys introduced CyberSecurity Asset Management 3.0Yesterday Qualys introduced CyberSecurity Asset Management 3.0

Yesterday Qualys introduced CyberSecurity Asset Management 3.0. The product name contains "Asset Management", but in the first sentence the solution is presented to us as "re-defining attack surface management" (EASM). Such a Gartner-style marketing mishmash. 🤷‍♂️ At the same time, Qualys does have quite unusual Asset Management and EASM. And it’s unusual how they came to this. These are solely my impressions as an outside observer; I do not have any insider information.

🔹 In 2020, Qualys introduced a Global AssetView solution. To put it simply, users could roll out Qualys cloud agents to hosts in the their infrastructure, deploy Qualys Passive Sensor to search for unknown assets in network traffic, and based on this get some basic understanding of their infrastructure (without detecting vulnerabilities). And most importantly, it's all free! This is a Freemium offer that allowed the company to conveniently upsell the functionality of Vulnerability Management and Compliance Management. The move is very, very bold.

🔹 In 2021, as a development of Global AssetView, the CyberSecurity Asset Management product appeared. This was already a full-fledged Asset Management: two-way synchronization with ServiceNow CMDB, asset criticality assessment, analysis of installed software, attack surface analysis using Shodan (the last option was not particularly emphasized back then). As far as I can understand, the original purpose of CSAM was to deal with cases that affect the security of assets, but are not, strictly speaking, vulnerabilities: shadow IT, upcoming end-of-life (EoL)-of-support (EoS) hosts, hosts without installed EDR, risky ports accessible from the Internet, misconfigurations of software and services.

🔹 In 2022, Qualys released CyberSecurity Asset Management 2.0 with an integrated External Attack Surface Management (EASM) solution. The idea that EASM can be developed and delivered as part of an Asset Management solution is quite unusual. But there is logic in this. Reducing the attack surface is not about patching this or that vulnerable server. This is about the fact that there should not be any unnecessary junk ("if an externally facing asset or its configuration is not necessary for the business, then it should be shut down"). And from this point of view, EASM is really not so much a perimeter scanner. It is rather a cunning utility that lists non-obvious assets that are, with some probability, related to the company, and shows the risks associated with them. 🐇 🎩 Is this part of Аsset Management? Well, apparently so.

So, as far as I understand, Qualys now has VMDR (Vulnerability Management, Detection and Response), which includes CSAM (CyberSecurity Asset Management ), which in turn includes EASM (External Attack Surface Management). Something like a matryoshka. 🪆

What's in CSAM 3.0?

🔻 Qualys removed mentions of Shodan. "CSAM 3.0 uses new attribution scoring and expands the use of open-source technology and a proprietary internet scanner to drive accurate discovery, attribution, and vulnerability assessment". When attributing an asset, attribution scoring are displayed (you can filter by them).

🔻Cloud Agent Passive Sensing asset detection capabilities are now used (host agents that sniff traffic).

🔻Connectors for integration with asset data sources (connectors for Active Directory and BMC Helix announced). Apparently there was no integration with AD before.🤷‍♂️

На русском

Getting public IP address ranges for an organization

Getting public IP address ranges for an organization. Small bash script to automate the work with Qrator Radar public API.

Qrator Radar

The idea is to get autonomous system (AS) number of the organization by it’s name and retrieve all related IPv4 Prefixes. Why you may need it? To be sure, for example, that you scan all the hosts of organization available from the Internet for vulnerability management, penetration testing or bug bounty activity. For smaller organizations that don’t have own AS that obviously will not work.

Continue reading