⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and the takedown of the GlassWorm C2 infrastructure. The article highlights the accelerating pace of attacks fueled by AI and emphasizes the importance of rapid patching and vigilance within open-source ecosystems.
The week's security news is dominated by multiple active exploits and ongoing campaigns. A significant concern is the exploitation of a medium-severity vulnerability (CVE-2026-0257) within Palo Alto Networks’ PAN-OS and Prisma Access, allowing unauthorized VPN connections. This vulnerability stems from misconfigured authentication override cookies and certificate configurations, and is already being leveraged by malicious actors. Simultaneously, the open-source Git service Gogs is facing a critical zero-day vulnerability, allowing remote code execution via malicious pull requests. This flaw, impacting Gogs servers across multiple operating systems, presents a significant risk due to the service's default open registration and repository creation policies.
Furthermore, the GlassWorm C2 operation, previously conducted through trojanized VS Code extensions, has been neutralized by a coordinated effort between CrowdStrike, Google, and the Shadowserver Foundation. This operation, originating from Russia, utilized compromised npm and Python packages to spread its malware. Despite the takedown, the article stresses that this is a temporary disruption, highlighting the ongoing challenges of abuse within open-source ecosystems and the accelerating impact of AI on attack timelines. Finally, CERT-In issued a call to action for Indian organizations to patch actively exploited vulnerabilities within 12 hours, reflecting the urgency driven by AI-powered attacks.
