Tag Archive for: altOS

Palo Alto’s Unit 42 team reveals new wave of PAN-OS firewall hack attempts


PAN-OS firewalls are facing an “increasing number of attacks”, though so far, signs of active command execution are rare.

Palo Alto’s PAN-OS firewalls are coming under increasing attack following the company’s disclosure of a command injection vulnerability on 12 April.

A few days later, the Australian Signals Directorate’s Australian Cyber Security Centre circulated a critical alert over the vulnerability, warning Australian organisations using Palo Alto’s firewalls to “act now” to mitigate the vulnerability, while Palo Alto said it was working on a hotfix.

Now, Palo Alto’s Unit 42 has shared more details of how the vulnerability – CVE-2024-3400, which could allow a threat actor to run arbitrary code on affected PAN-OS firewalls – is being actively exploited.

The big brains at Unit 42 have broken down the exploitation attempts into four discrete groups.

At level zero, we have threat actors simply probing customer networks and failing to make any kind of access. Unit 42 expected these attempts to have “little to no immediate impact” on organisations, and simply applying the available hotfix should remedy the situation.

Unit 42 rates level one as threat actors actively testing the vulnerability. In this case, “a zero-byte file has been created and is resident on the firewall. However, there is no indication of any known unauthorised command execution.”

Again, applying Palo Alto’s hotfix should do the trick.

In both cases, Unit 42 believes resetting the impacted device is unnecessary, as there is no indication of active compromise or data exfiltration.

At level two, however, Unit 42 is beginning to see “potential exfiltration” of data.

“A file on the device has been copied to a location accessible via a web request, though the file may or may not have been subsequently downloaded,” Unit 42 said in a blog post. “Typically, the file we have observed being copied is running_config.xml.”

Unit 42’s advice in this case is to both install the hotfix and perform a private data reset.

“Private data reset clears all logs and reverts the configuration to factory defaults,” Unit 42 said. “The system will restart…

Source…

CIS Mobile Announces altOS on 5G Smartphones


ASHBURN, Va., May 11, 2021 /PRNewswire/ — CIS Mobile, a mobile security leader, today announces the availability of altOS on Pixel 4a 5G and Pixel 5 smartphones. By combining the latest 5G-enabled Pixel hardware and our altOS secure mobility platform, government customers can protect their missions while using the latest high-performance, low-cost smartphones.

CIS Mobile’s altOS is a security-enhanced Android operating system designed with the security, privacy, and control capabilities needed for sensitive government use cases.  It is used by multiple government intelligence and defense agencies around the world.

The Pixel 4a 5G and Pixel 5 are the first altOS devices to support 5G technology, which is set to power the next wave of mobile connectivity and smart devices. 5G networks provide unrivaled speeds and richer security to devices on the network, accelerating services while securing data.

“5G networks enable powerful new applications and services to be delivered quickly and reliably to our government customers.  CIS Mobile’s new release on 5G phones combines the enhanced security controls and capabilities of the altOS platform with the latest high speed communications networks,” said Bill Anderson, President of CIS Mobile

altOS on 5G smartphones is available today to new and existing customers and partners, and will be rolled out to existing deployments in the coming weeks.  CIS Mobile installs altOS in our secure facilities to ensure a hardware-backed root of trust for the whole platform.   

About CIS Mobile

CIS Mobile is a subsidiary of CIS Secure, an industry leader and global provider for designing and manufacturing secure communications and computing solutions for Governments and Enterprises. With headquarters in the Washington, DC metropolitan area, the company operates a state-of-the-art 65,000 square foot NSA certified TEMPEST manufacturing and testing facility.

CIS Mobile has a mission to address Government needs for a modern, convenient, and secure mobility platform.

For additional information, visit our website: https://cismobile.com/.

CIS Mobile Media Contact:

Jonas Greene
+1 (703) 996-0500
[email protected]

SOURCE CIS Mobile

Related…

Source…