Visualização de leitura

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe.

China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that.

“To ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security, in accordance with the National Security Law of the People’s Republic of China and the Cybersecurity Law of the People’s Republic of China, the Cybersecurity Review Office, following the Cybersecurity Review Measures, has conducted a cybersecurity review of Palo Alto Networks’ products sold in China.” the regulator says.

That’s the entire public justification. No specific vulnerability named, no incident referenced, no timeline for when findings might land. Palo Alto Networks told The Register it maintains high standards across its global operations and that, for now, there’s no impact on its ability to serve customers or deliver products in the region.

The situation resembles China’s 2023 security review of Micron, which was announced without warning. Weeks later, Beijing deemed Micron’s products a security risk for critical infrastructure, effectively restricting sales, but provided little explanation. Micron eventually withdrew its data center and server products from China, losing billions in annual revenue while local chipmakers gained new opportunities.

Micron’s story offers one genuinely reassuring data point for Palo Alto, if it’s any comfort: getting banned from a major market didn’t permanently damage the company. The AI boom drove memory prices high enough afterward that the China restriction barely shows up in Micron’s financials today. Getting frozen out of a market stings a lot less when the rest of the world is buying everything you can produce anyway.

China has already been pushing companies away from foreign cybersecurity products: in January, authorities reportedly told Chinese firms to stop using security software from a list of U.S. and Israeli vendors that included Palo Alto Networks, Fortinet, Check Point, CrowdStrike and others, encouraging the replacement of those products with domestic alternatives. Chinese vendors such as Huawei and H3C have increasingly positioned their own firewalls and security platforms as alternatives to foreign products, while other domestic companies are expanding across the cybersecurity market. H3C, for example, openly promotes its security products as replacements for overseas technologies.

That makes the Palo Alto review more than a simple technical investigation. It fits a broader strategy in which cybersecurity and national security are increasingly intertwined with China’s push for technological self-reliance.

For Palo Alto, the immediate financial impact is difficult to measure because the company does not separately report China revenue, but restrictions could still create an opening for domestic competitors while adding another layer of uncertainty for Western technology companies operating in the country.

There is also a wider geopolitical dimension. Beijing has repeatedly framed foreign technology as a potential national-security risk, while Washington and its allies have taken similar measures against Chinese and Russian vendors, including Huawei, ZTE and Kaspersky. The United States, for example, banned Kaspersky’s cybersecurity and antivirus products over national-security concerns, arguing that the software created risks because of its ties to Russia. The Palo Alto case therefore sits within a much larger cycle of reciprocal distrust, in which cybersecurity products are increasingly treated not only as commercial technologies but also as potential strategic assets.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, China)

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks.

Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks.

CVE-2026-0257 is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.

Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. In early June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability affects the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS, allowing attackers to bypass authentication and establish unauthorized VPN connections. The vulnerabilities do not affect Panorama or Cloud NGFW deployments.

“Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.” reads the advisory.

Arctic Wolf warns that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. The flaw allows attackers to bypass authentication and establish unauthorized VPN sessions on unpatched devices. Palo Alto Networks released patches on May 13 and confirmed exploitation attempts against systems that had not applied updates or mitigations.

Arctic Wolf Labs has observed several attacks in which threat actors exploited CVE-2026-0257 to gain initial access and deploy Qilin ransomware across entire Windows domains. Investigators found evidence that multiple Qilin affiliates are actively abusing the flaw to compromise organizations, making unpatched PAN-OS GlobalProtect devices a high-priority target for ransomware operations.

“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.” reads the report published by Arctic Wolf. “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella.”

Arctic Wolf found that attacks exploiting CVE-2026-0257 followed a common initial pattern but diverged after compromise. Threat actors consistently used the same entry point, ransomware staging paths, PsExec execution, and registry persistence. However, some attacks quickly encrypted entire environments without stealing data, while others involved extensive reconnaissance, deployment of remote-access tools such as AnyDesk, Ngrok, and LogMeIn, large-scale credential theft, and data exfiltration to cloud services before ransomware execution, reflecting the varied tactics of Qilin RaaS affiliates.

After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent. They harvested credentials by dumping LSASS memory and extracting the Active Directory database (NTDS), enabling lateral movement with PsExec, RDP, and compromised administrator accounts.

The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware. Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.

The ransomware payload, typically named win.exe, was staged in C:\PerfLogs, executed with password-protected parameters, and encrypted files using unique extensions assigned to each campaign.

“The variability in post-exploitation tradecraft, from encryption-only operations to full double-extortion, shows that perimeter compromise is the critical point for defenders. After exploitation succeeds, the impact depends on the affiliate’s goals and timeline, but domain compromise and ransomware deployment are consistent.” concludes the report. “Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model’s tendency to distribute successful exploits among multiple affiliates.”

Qilin ransomware operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.

The group enables affiliates to deploy customized ransomware payloads against targeted organizations. Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals. The group has targeted multiple sectors worldwide, including healthcare, manufacturing, and finance, leveraging phishing and known vulnerabilities.

In October 2025, Resecurity’s researchers detailed how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.

In early October, DragonForceLockBit, and Qilin formed a ransomware alliance to boost attack effectiveness, marking a major shift in the cyber threat landscape. Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape. The alliance aims at sharing tools and infrastructure to enhance attack effectiveness. 

At the end of March, Qilin Ransomware group allegedly breached the chemical manufacturing giant Dow Inc. 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

PAN-OS Flaw CVE-2026-0300 Exposes Firewalls to Remote Code Execution

Buffer Overflow Vulnerability

A newly disclosed cybersecurity issue, tracked as CVE-2026-0300, has drawn urgent attention due to its critical severity and active exploitation. The flaw affects PAN-OS, the operating system used in Palo Alto Networks firewalls, and has been categorized as a buffer overflow vulnerability with serious implications for enterprise security environments.  The CVE-2026-0300 PAN-OS vulnerability was officially published on May 6, 2026, and updated the same day after being discovered in real-world production environments. It carries a CVSS score of 9.3, placing it firmly in the “critical” category. The issue stems from a buffer overflow vulnerability in the User-ID Authentication Portal, also known as the Captive Portal service, within PAN-OS.  This flaw allows an unauthenticated attacker to execute arbitrary code with root privileges by sending specially crafted network packets. Because the attack requires no authentication, no user interaction, and can be carried out over the network with low complexity, the exposure risk is considered extremely high. 

Technical Details of the Buffer Overflow Vulnerability in PAN-OS 

The root cause of CVE-2026-0300 PAN-OS is classified under CWE-787: Out-of-bounds Write, a common but dangerous type of buffer overflow vulnerability. Attackers can exploit this flaw to overwrite memory and potentially take full control of affected systems.  The vulnerability impacts PA-Series and VM-Series firewalls when the User-ID™ Authentication Portal is enabled. Importantly, Prisma Access, Cloud NGFW, and Panorama appliances are not affected.  Security data associated with the vulnerability highlights the following: 
  • Attack Vector: Network  
  • Attack Complexity: Low  
  • Privileges Required: None  
  • User Interaction: None  
  • Confidentiality, Integrity, Availability Impact: High  
Additionally, the vulnerability is automatable and has already reached the “ATTACKED” stage in exploit maturity, indicating that real-world attacks have been observed. 

Active Exploitation and Risk Factors 

Evidence shows limited exploitation of CVE-2026-0300 PAN-OS, particularly targeting systems where the User-ID Authentication Portal is exposed to untrusted networks or the public internet. Environments that allow external access to this portal face the highest level of risk. The severity is further highlighted by the CVSS vector:  CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H  This translates to a scenario where attackers can remotely compromise systems without needing credentials or user involvement, leveraging the buffer overflow vulnerability to gain root-level access. 

Affected and Unaffected Versions 

Multiple versions of PAN-OS are impacted by CVE-2026-0300, including: 
  • PAN-OS 12.1 versions prior to 12.1.4-h5 and 12.1.7  
  • PAN-OS 11.2 versions prior to 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, and 11.2.12  
  • PAN-OS 11.1 versions prior to 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, and 11.1.15  
  • PAN-OS 10.2 versions prior to 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, and 10.2.18-h6  
Patches are scheduled with estimated availability dates ranging from May 13 to May 28, 2026. Cloud NGFW and Prisma Access deployments remain unaffected. 

Mitigation and Workarounds 

While patches are being rolled out, organizations are advised to take immediate steps to reduce exposure to the buffer overflow vulnerability in PAN-OS.  Recommended mitigations include: 
  • Restricting access to the User-ID Authentication Portal to trusted internal IP addresses only  
  • Preventing any exposure of the portal to the public internet  
  • Disabling the User-ID Authentication Portal entirely if it is not required  
The risk associated with CVE-2026-0300 PAN-OS drops significantly when these best practices are implemented. Systems that already follow strict network segmentation and access control policies are at a much lower risk. 

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

A hacktivist group with links to Iran’s intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker’s largest hub outside of the United States, said the company sent home more than 5,000 workers there today. Meanwhile, a voicemail message at Stryker’s main U.S. headquarters says the company is currently experiencing a building emergency.

Based in Kalamazoo, Michigan, Stryker [NYSE:SYK] is a medical and surgical equipment maker that reported $25 billion in global sales last year. In a lengthy statement posted to Telegram, a hacktivist group known as Handala (a.k.a. Handala Hack Team) claimed that Stryker’s offices in 79 countries have been forced to shut down after the group erased data from more than 200,000 systems, servers and mobile devices.

A manifesto posted by the Iran-backed hacktivist group Handala, claiming a mass data-wiping attack against medical technology maker Stryker.

A manifesto posted by the Iran-backed hacktivist group Handala, claiming a mass data-wiping attack against medical technology maker Stryker.

“All the acquired data is now in the hands of the free people of the world, ready to be used for the true advancement of humanity and the exposure of injustice and corruption,” a portion of the Handala statement reads.

The group said the wiper attack was in retaliation for a Feb. 28 missile strike that hit an Iranian school and killed at least 175 people, most of them children. The New York Times reports today that an ongoing military investigation has determined the United States is responsible for the deadly Tomahawk missile strike.

Handala was one of several hacker groups recently profiled by Palo Alto Networks, which links it to Iran’s Ministry of Intelligence and Security (MOIS). Palo Alto says Handala surfaced in late 2023 and is assessed as one of several online personas maintained by Void Manticore, a MOIS-affiliated actor.

Stryker’s website says the company has 56,000 employees in 61 countries. A phone call placed Wednesday morning to the media line at Stryker’s Michigan headquarters sent this author to a voicemail message that stated, “We are currently experiencing a building emergency. Please try your call again later.”

A report Wednesday morning from the Irish Examiner said Stryker staff are now communicating via WhatsApp for any updates on when they can return to work. The story quoted an unnamed employee saying anything connected to the network is down, and that “anyone with Microsoft Outlook on their personal phones had their devices wiped.”

“Multiple sources have said that systems in the Cork headquarters have been ‘shut down’ and that Stryker devices held by employees have been wiped out,” the Examiner reported. “The login pages coming up on these devices have been defaced with the Handala logo.”

Wiper attacks usually involve malicious software designed to overwrite any existing data on infected devices. But a trusted source with knowledge of the attack who spoke on condition of anonymity told KrebsOnSecurity the perpetrators in this case appear to have used a Microsoft service called Microsoft Intune to issue a ‘remote wipe’ command against all connected devices.

Intune is a cloud-based solution built for IT teams to enforce security and data compliance policies, and it provides a single, web-based administrative console to monitor and control devices regardless of location. The Intune connection is supported by this Reddit discussion on the Stryker outage, where several users who claimed to be Stryker employees said they were told to uninstall Intune urgently.

Palo Alto says Handala’s hack-and-leak activity is primarily focused on Israel, with occasional targeting outside that scope when it serves a specific agenda. The security firm said Handala also has taken credit for recent attacks against fuel systems in Jordan and an Israeli energy exploration company.

“Recent observed activities are opportunistic and ‘quick and dirty,’ with a noticeable focus on supply-chain footholds (e.g., IT/service providers) to reach downstream victims, followed by ‘proof’ posts to amplify credibility and intimidate targets,” Palo Alto researchers wrote.

The Handala manifesto posted to Telegram referred to Stryker as a “Zionist-rooted corporation,” which may be a reference to the company’s 2019 acquisition of the Israeli company OrthoSpace.

Stryker is a major supplier of medical devices, and the ongoing attack is already affecting healthcare providers. One healthcare professional at a major university medical system in the United States told KrebsOnSecurity they are currently unable to order surgical supplies that they normally source through Stryker.

“This is a real-world supply chain attack,” the expert said, who asked to remain anonymous because they were not authorized to speak to the press. “Pretty much every hospital in the U.S. that performs surgeries uses their supplies.”

John Riggi, national advisor for the American Hospital Association (AHA), said the AHA is not aware of any supply-chain disruptions as of yet.

“We are aware of reports of the cyber attack against Stryker and are actively exchanging information with the hospital field and the federal government to understand the nature of the threat and assess any impact to hospital operations,” Riggi said in an email. “As of this time, we are not aware of any direct impacts or disruptions to U.S. hospitals as a result of this attack. That may change as hospitals evaluate services, technology and supply chain related to Stryker and if the duration of the attack extends.”

According to a March 11 memo from the state of Maryland’s Institute for Emergency Medical Services Systems, Stryker indicated that some of their computer systems have been impacted by a “global network disruption.” The memo indicates that in response to the attack, a number of hospitals have opted to disconnect from Stryker’s various online services, including LifeNet, which allows paramedics to transmit EKGs to emergency physicians so that heart attack patients can expedite their treatment when they arrive at the hospital.

“As a precaution, some hospitals have temporarily suspended their connection to Stryker systems, including LIFENET, while others have maintained the connection,” wrote Timothy Chizmar, the state’s EMS medical director. “The Maryland Medical Protocols for EMS requires ECG transmission for patients with acute coronary syndrome (or STEMI). However, if you are unable to transmit a 12 Lead ECG to a receiving hospital, you should initiate radio consultation and describe the findings on the ECG.”

This is a developing story. Updates will be noted with a timestamp.

Update, 2:54 p.m. ET: Added comment from Riggi and perspectives on this attack’s potential to turn into a supply-chain problem for the healthcare system.

Update, Mar. 12, 7:59 a.m. ET: Added information about the outage affecting Stryker’s online services.

Cibercriminosos adotam agentes de IA para lançar ataques autônomos e adaptáveis em 2025

De acordo com um estudo publicado pelo Observatório Latino-Americano de Ameaças Digitais (OLAD) em 2025, 411 ataques cibernéticos e ameaças digitais direcionados a empresas e instituições na América Latina foram documentados durante o ano passado, incluindo infraestruturas críticas como alvos, espionagem e ransomware.

À medida que os recursos de defesa de IA evoluem, o mesmo acontece com as estratégias e ferramentas de IA utilizadas pelos agentes de ameaças, criando um cenário de riscos em rápida transformação que superam os métodos tradicionais de detecção e respostas. Nesse contexto, a nova pesquisa da Unit 42, equipe de inteligência de ameaças da Palo Alto Networks, intitulada Agentic AI Attack Framework, revelou como os criminosos estão começando a usar os agentes, uma evolução da inteligência artificial que vai além da geração de conteúdo a qual, ao contrário da generativa, que se concentra na criação de texto, imagens ou código, depende somente de agentes autônomos capazes de tomar decisões, adaptar ao ambiente e executar várias fases de um ataque cibernético sem intervenção humana direta.

O relatório detalha como esses agentes podem ser programados para executar tarefas como inspeção do sistema, escrever e-mails de phishing personalizados, evitar controles de segurança, manipular conversas em tempo real e remover rastros digitais. O mais preocupante é que eles podem aprender com os erros, ajustar o próprio comportamento e colaborar entre si, o que os torna uma ameaça muito mais dinâmica e difícil de conter.

Durante os testes, a Unit 42 simulou um ataque de ransomware, desde o comprometimento inicial até a exfiltração de dados, em apenas 25 minutos, usando IA em cada estágio da cadeia de ataque. Isso representou um aumento de 100 vezes na velocidade, totalmente impulsionado por IA.

Em contraste com os ciberataques tradicionais, que normalmente seguem padrões previsíveis e exigem intervenção humana em cada estágio, os ataques agênticos podem operar de forma contínua e adaptável. Isso significa que um único agente pode iniciar uma campanha de invasão, avaliar seu progresso, modificar sua estratégia em tempo real e escalar o ataque sem a necessidade de supervisão direta. Essa capacidade de ser autônomo representa um desafio para as equipes de cibersegurança, que precisam lidar com ameaças que não são apenas mais rápidas, como também mais inteligentes e persistentes.

Esses ataques cibernéticos podem ter consequências graves para as organizações. Por exemplo, um agente mal-intencionado pode enviar e-mails falsos altamente convincentes aos funcionários para roubar senhas, se infiltrar em sistemas internos e circular pela rede sem ser detectado. Isso leva ao roubo de informações confidenciais, como dados de clientes ou planos estratégicos, ou até mesmo ao sequestro de sistemas importantes por ransomware, paralisando as operações por dias. Além do impacto econômico, esses incidentes prejudicam a reputação da empresa, geram uma perda de confiança e podem levar a sanções legais se informações pessoais ou financeiras forem comprometidas.

Preparando-se para o imprevisível: como fortalecer a segurança organizacional

Nesse cenário, as organizações precisam de uma infraestrutura de segurança avançada e adaptável. Não é mais suficiente reagir a incidentes, agora é essencial antecipá-los por meio de monitoramento contínuo, análise inteligente de dados e automação dos principais processos.

A tendência à plataformização permite que as empresas reduzam a fragmentação tecnológica, melhorem a visibilidade do próprio ambiente digital e respondam mais rapidamente a qualquer tentativa de invasão. A Palo Alto Networks, por exemplo, está fazendo algo exatamente nesse sentido, desenvolvendo uma plataforma unificada de segurança de dados que abrangerá desde o desenvolvimento de código até ambientes de nuvem e centros de operações de segurança (SOCs). Essa iniciativa busca oferecer uma visão holística da segurança e facilitar o gerenciamento centralizado de ameaças, o que é essencial diante de um cenário de ataques cibernéticos cada vez mais sofisticados.

Além disso, a adoção de arquiteturas como o SASE (Secure Access Service Edge) fortalece a postura de segurança ao estender a proteção para além do perímetro tradicional. Essas tecnologias permitem controles granulares baseados em identidade, contexto e comportamento, o que é fundamental em um ambiente em que usuários, dispositivos e aplicativos estão distribuídos. Para as organizações brasileiras, investir nesse tipo de recurso representa uma melhoria técnica, bem como uma estratégia fundamental para garantir a continuidade operacional e a proteção de ativos essenciais contra ameaças cada vez mais automatizadas e persistentes.

O Brasil, com a crescente digitalização em setores-chave, como saúde, educação e serviços públicos, se torna um alvo atraente para essa ameaça emergente. A necessidade de fortalecer as capacidades de segurança cibernética no país é urgente, especialmente em face da adoção acelerada de tecnologias digitais em todos os níveis do governo e das empresas.

Diante desse cenário, especialistas da Palo Alto Networks recomendam que as organizações brasileiras implementem soluções de segurança que integrem recursos de detecção baseados em IA, bem como programas de conscientização e resposta a incidentes que considerem esse novo tipo de ameaças automatizadas.

A evolução dos ataques cibernéticos para esquemas mais autônomos e adaptáveis exige uma resposta igualmente inovadora. Somente por meio de estratégias proativas e colaborativas será possível mitigar os riscos apresentados por essa nova era de ataques alimentados pelos agentes de IA.

Sobre a Unit 42

A Unit 42 da Palo Alto Networks reúne pesquisadores de ameaças de renome mundial, respondentes de incidentes de elite e consultores de segurança especializados para criar uma organização orientada por inteligência e pronta para responder, apaixonada por ajudar a gerenciar o risco cibernético proativamente. Juntos, nossa equipe atua como seu consultor de confiança para ajudar a avaliar e testar controles de segurança contra as ameaças certas, transformar estratégias de segurança com uma abordagem informada sobre ameaças e responder a incidentes em tempo recorde para que você possa voltar aos negócios mais rapidamente. Visite paloaltonetworks.com/unit42.

Sobre a Palo Alto Networks

Como líder global em segurança cibernética, a Palo Alto Networks (NASDAQ: PANW) tem o compromisso de proteger nosso modo de vida digital por meio de inovação contínua. Com a confiança de organizações em todo o mundo, fornecemos soluções de segurança de ponta a ponta baseadas em IA em redes, nuvem, operações de segurança e IA, capacitadas pela inteligência e experiência em ameaças da Unit 42. Nosso foco na plataformização permite que as empresas simplifiquem a segurança em escala, garantindo que a proteção impulsione a inovação. Saiba mais em www.paloaltonetworks.com.

CVEs Targeting Remote Access Technologies in 2025

The exploitation of vulnerabilities targeting remote access technologies to gain initial access is continuing relentlessly also during 2025, with initial access brokers, and in general opportunistic and targeted threat actors, quite active in leveraging software flaws to break into organizations.
❌