{"id":219506,"date":"2026-05-25T03:25:07","date_gmt":"2026-05-25T07:25:07","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/25\/palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking\/"},"modified":"2026-05-25T03:25:09","modified_gmt":"2026-05-25T07:25:09","slug":"palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/25\/palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking\/","title":{"rendered":"Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking"},"content":{"rendered":"<p><a href=\"https:\/\/www.securityweek.com\/palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking\/\">Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking<\/a><\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking\/\">https:\/\/www.securityweek.com\/palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-07 11:31:12<\/a><\/p>\n<p>Source Domain: <a href=\"www.securityweek.com\">www.securityweek.com<\/a><\/p>\n<p><strong>Summary:<\/strong><br \/>\nPalo Alto Networks disclosed a critical zero-day vulnerability (CVE-2026-0300) impacting its User-ID Authentication Portal of PA and VM series firewalls that allows remote code execution with root privileges. The cybersecurity firm detected exploitation attempts attributed to a &#8220;likely state-sponsored&#8221; threat group referred to as CL-STA-1132, showing evidence pointing towards Chinese actors based on their use of open-source tools like Earthworm and ReverseSocks5, log destruction tactics, and Active Directory targeting. Exploitation attempts initially failed but succeeded a week later, with attackers deploying the tools before extensively cleaning logs, deleting critical evidence, and escalating privileges. Palo Alto Networks advises customers on mitigations and patches are scheduled for May 13 and May 28.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>Palo Alto Networks disclosed a zero-day vulnerability CVE-2026-0300 affecting its firewalls allowing remote code execution.<\/li>\n<li>Evidence suggests state-sponsored exploitation, likely conducted by a group traced as CL-STA-1132, pointing towards Chinese threat actors.<\/li>\n<li>Exploits involved log destruction and the deployment of tools like Earthworm and ReverseSocks5 to facilitate covert communications and bypass firewalls.<\/li>\n<li>Attackers conducted Active Directory enumeration and deleted log evidence to evade detection.<\/li>\n<li>Patches are scheduled for release on May 13 and May 28, with interim mitigation strategies provided.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking https:\/\/www.securityweek.com\/palo-alto-zero-day-exploited-in-campaign-bearing-hallmarks-of-chinese-state-hacking\/ Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":219507,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.securityweek.com\/wp-content\/uploads\/2024\/11\/Palo-Alto-Networks-zero-day.jpeg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,27],"class_list":["post-219506","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/219506"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=219506"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/219506\/revisions"}],"predecessor-version":[{"id":219508,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/219506\/revisions\/219508"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/219507"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=219506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=219506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=219506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}