[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/network-attacks-trends-august-october-2021/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/network-attacks-trends-august-october-2021/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/ "Trend Reports")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Network Security Trends: August-October 2021

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Yue Guan](https://unit42.paloaltonetworks.com/author/yue-guan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:December 21, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/)
  * [Buffer Overflow](https://unit42.paloaltonetworks.com/tag/buffer-overflow/)
  * [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/)
  * [Cross-site request forgery](https://unit42.paloaltonetworks.com/tag/cross-site-request-forgery/)
  * [Cross-site scripting](https://unit42.paloaltonetworks.com/tag/cross-site-scripting/)
  * [CVE-2021-24499](https://unit42.paloaltonetworks.com/tag/cve-2021-24499/)
  * [CVE-2021-26084](https://unit42.paloaltonetworks.com/tag/cve-2021-26084/)
  * [CVE-2021-32789](https://unit42.paloaltonetworks.com/tag/cve-2021-32789/)
  * [CVE-2021-33357](https://unit42.paloaltonetworks.com/tag/cve-2021-33357/)
  * [CVE-2021-33766](https://unit42.paloaltonetworks.com/tag/cve-2021-33766/)
  * [CVE-2021-34473](https://unit42.paloaltonetworks.com/tag/cve-2021-34473/)
  * [CVE-2021-35395](https://unit42.paloaltonetworks.com/tag/cve-2021-35395/)
  * [CVE-2021-38647](https://unit42.paloaltonetworks.com/tag/cve-2021-38647/)
  * [CVE-2021-40438](https://unit42.paloaltonetworks.com/tag/cve-2021-40438/)
  * [CVE-2021-40870](https://unit42.paloaltonetworks.com/tag/cve-2021-40870/)
  * [CVE-2021-41773](https://unit42.paloaltonetworks.com/tag/cve-2021-41773/)
  * [CVE-2021-42013](https://unit42.paloaltonetworks.com/tag/cve-2021-42013/)
  * [Denial of service](https://unit42.paloaltonetworks.com/tag/denial-of-service/)
  * [Directory traversal](https://unit42.paloaltonetworks.com/tag/directory-traversal/)
  * [Exploit in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/)
  * [Improper authentication](https://unit42.paloaltonetworks.com/tag/improper-authentication/)
  * [Information disclosure](https://unit42.paloaltonetworks.com/tag/information-disclosure/)
  * [Memory corruption](https://unit42.paloaltonetworks.com/tag/memory-corruption/)
  * [Network security trends](https://unit42.paloaltonetworks.com/tag/network-security-trends/)
  * [Out-of-bounds read](https://unit42.paloaltonetworks.com/tag/out-of-bounds-read/)
  * [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/)
  * [Remote Code Execution](https://unit42.paloaltonetworks.com/tag/remote-code-execution/)
  * [Security feature bypass](https://unit42.paloaltonetworks.com/tag/security-feature-bypass/)
  * [SQL injection](https://unit42.paloaltonetworks.com/tag/sql-injection/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/network-attacks-trends-august-october-2021/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/network-attacks-trends-august-october-2021/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Network%20Security%20Trends:%20August-October%202021&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fnetwork-attacks-trends-august-october-2021%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnetwork-attacks-trends-august-october-2021%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnetwork-attacks-trends-august-october-2021%2F&title=Network%20Security%20Trends:%20August-October%202021 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnetwork-attacks-trends-august-october-2021%2F&text=Network%20Security%20Trends:%20August-October%202021 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnetwork-attacks-trends-august-october-2021%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Network%20Security%20Trends:%20August-October%202021%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fnetwork-attacks-trends-august-october-2021%2F "Share in Mastodon")

## **Executive Summary**

Unit 42 researchers continually observe network attacks and search for insights that can assist defenders. Here, we summarize key trends from August-October 2021. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, say, cross-site scripting or denial of service.

Additionally, we provide insight into how the vulnerabilities are actively exploited in the wild based on real-world data collected from [Palo Alto Networks Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall). For example, we chart a timeframe showing how frequently the most commonly exploited vulnerabilities were attacked through networks and the locations from which the attacks appeared to originate. We then draw conclusions about the most commonly exploited vulnerabilities the attackers are using, as well as the severity, category and origin of each attack.

Cross-site scripting stood out as a commonly used technique. Among around 7,000 newly published vulnerabilities, we found that a large portion (almost 15%) still involve this technique. However, by evaluating around 3.8 million attack sessions and focusing on the latest exploits in the wild, we conclude that code execution is still a great concern, while directory traversal is ranking more highly when we categorize those attacks. Defenders should pay attention to the trends and adjust mitigation methodology accordingly.

Palo Alto Networks Next Generation Firewall customers are protected from the vulnerabilities discussed here by [cloud-delivered security subscriptions](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering).

|----------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CVEs Discussed                               | [CVE-2021-40438](https://nvd.nist.gov/vuln/detail/CVE-2021-40438), [CVE-2021-34473](https://nvd.nist.gov/vuln/detail/CVE-2021-34473), [CVE-2021-38647](https://unit42.paloaltonetworks.com/tag/cve-2021-38647/), [CVE-2021-26084](https://unit42.paloaltonetworks.com/tag/cve-2021-26084/), [CVE-2021-40870](https://nvd.nist.gov/vuln/detail/CVE-2021-40870), [CVE-2021-33357](https://nvd.nist.gov/vuln/detail/CVE-2021-33357), [CVE-2021-35395](https://nvd.nist.gov/vuln/detail/CVE-2021-35395), [CVE-2021-24499](https://nvd.nist.gov/vuln/detail/CVE-2021-24499), [CVE-2021-33766](https://nvd.nist.gov/vuln/detail/CVE-2021-33766), [CVE-2021-32789](https://nvd.nist.gov/vuln/detail/CVE-2021-32789), [CVE-2021-41773](https://nvd.nist.gov/vuln/detail/CVE-2021-41773), [CVE-2021-42013](https://nvd.nist.gov/vuln/detail/CVE-2021-42013) |
| Types of Attacks and Vulnerabilities Covered | Cross-site scripting, denial of service, information disclosure, buffer overflow, privilege escalation, memory corruption, code execution, SQL injection, out-of-bounds read, cross-site request forgery, directory traversal, command injection, improper authentication, security feature bypass                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Affected Software                            | Apache HTTP Server, Microsoft Exchange Server, Microsoft OMI, Confluence Server and Data Center, Aviatrix Controller, RaspAP, Realtek Jungle SDK, Workreap WordPress theme, WooCommerce Gutenberg Blocks                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Related Unit 42 Topics                       | [Network Security Trends](https://unit42.paloaltonetworks.com/tag/network-security-trends/), [exploits in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/), [attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

## **Analysis of Published Vulnerabilities, August-October 2021**

From August-October 2021, a total of 7,064 new Common Vulnerabilities and Exposures (CVE) numbers were registered. To better understand the potential impact these newly published vulnerabilities could have on network security, we provide our observations based on the severity, proof-of-concept code feasibility and vulnerability categories.

### **How Severe Are the Latest Vulnerabilities?**

To estimate the potential impact of vulnerabilities, we consider their severity and examine any reliable proofs-of-concept (PoCs) that are available. Some of the public sources we use to find PoCs are Exploit-DB, GitHub and Metasploit. Distribution for the 5,101 CVEs that have an assigned severity score of medium or higher can be seen in the following table:

|--------------|-----------|-----------|----------------------|
| **Severity** | **Count** | **Ratio** | **PoC Availability** |
| Critical     | 594       | 13.6%     | 6.2%                 |
| High         | 1965      | 45.1%     | 5.8%                 |
| Medium       | 2542      | 41.3%     | 6.1%                 |

^*Table 1. Severity distribution for CVEs registered in August-October 2021.*^
:chart: Figure 1. Severity distribution for CVEs registered in August-October 2021.

Vulnerabilities classified as critical are the least common, but they are also more likely to have PoCs available. The data suggests that there is a correlation between the availability of a PoC and the severity of a vulnerability. This could be influenced by the amount of attention a vulnerability receives when it is more severe, as it is more interesting to both security researchers and attackers. Palo Alto Networks continues to leverage threat intelligence information on the latest vulnerabilities and real-time monitoring of exploits in the wild to provide protections for our customers.

### **Vulnerability Category Distribution**

The type of vulnerability is also crucial to understanding its consequences. Out of the newly published CVEs that were analyzed, only 25.6% are classified as local vulnerabilities, requiring prior access to a compromised system, while the remaining 74.4% are remote vulnerabilities, which can be exploited over a network. This means that the majority of the newly published vulnerabilities introduce the potential for threat actors to attack vulnerable organizations anywhere in the world.

The most common vulnerability types are shown below, ranked by how prevalent they were among the most recent set of published vulnerabilities:

|-------------|----------------------------|
| **Ranking** | **Vulnerability Category** |
| 1           | Cross-Site Scripting       |
| 2           | Denial of Service          |
| 3           | Information Disclosure     |
| 4           | Buffer Overflow            |
| 5           | Privilege Escalation       |
| 6           | Memory Corruption          |
| 7           | Code Execution             |
| 8           | SQL Injection              |
| 9           | Out-of-Bounds Read         |
| 10          | Cross-Site Request Forgery |

^*Table 2. CVEs registered in August-October 2021, organized by category and ranked in terms of which categories contain the most vulnerabilities.*^
![Vulnerability category distribution for CVEs registered in August-October 2021, ranked by how prevalent the type of vulnerability is among recently registered CVEs. The categories, from most to least common, are cross-site scripting, denial of service, information disclosure, buffer overflow, privilege escalation, memory corruption, code execution, SQL injection, out-of-bounds read, cross-site request forgery, security feature bypass, NULL pointer dereference, improper authentication and command injection.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/chart-1.png) Figure 2. Vulnerability category distribution for CVEs registered in August-October 2021.

Cross-site scripting remains ranked first, and more denial-of-service vulnerabilities were published this quarter than last quarter. At the same time, the prevalence of code execution vulnerabilities increased in August-October 2021.

## **Network Security Trends: Analysis of Exploits in the Wild, August-October 2021**

### **Data Collection**

By leveraging Palo Alto Networks Next-Generation Firewalls as sensors on the perimeter, Unit 42 researchers observed malicious activities from August-October 2021. We analyzed more than 10 million sessions in total for this quarter. The malicious traffic we identify is further processed based on metrics such as IP addresses, port numbers and timestamps. This ensures the uniqueness of each attack session and thus eliminates potential data skews. We filtered out and finalized 3.79 million valid malicious sessions. We researchers then correlated the refined data with other attributes to infer attack trends over time to get a picture of the threat landscape.

### **How Severe Were the Attacks Exploited in the Wild?**

To arrive at 3.79 million valid malicious sessions, we exclude from the original set of more than 10 million the low-severity signature triggers that are used to detect scanning and brute-force attacks. Therefore, we consider exploitable vulnerabilities with a severity ranking of medium and higher (based on the [CVSS v3 Score](https://nvd.nist.gov/vuln-metrics/cvss)) as a verified attack.

|--------------|-----------|-----------|
| **Severity** | **Count** | **Ratio** |
| Critical     | 1,050,661 | 27.7%     |
| High         | 2,060,187 | 54.4%     |
| Medium       | 678,426   | 17.9%     |

^*Table 3. Attack severity distribution ratio in August-October 2021.*^
![Severity distribution of network attacks observed in August-October 2021. Critical - 27.7%, High - 54.4%, Medium - 17.9%](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/chart-2.png) Figure 3. Attack severity distribution in August-October 2021.

Table 3 shows the session count and ratio of attacks grouped by the severity of each vulnerability. Compared with the [previous quarters'](https://unit42.paloaltonetworks.com/tag/network-security-trends/) severity distribution, this quarter shows a noticeable increase in the prevalence of high-security attacks and a decrease in medium-severity attacks. High-severity attacks represent more than half of the observed attacks for the first time. However, we still focus most closely on critical severity attacks because of their greater potential impact. Even though many published vulnerabilities are medium severity, attackers leverage more severe vulnerabilities for exploits. Defenders should pay attention to prevention and mitigation of high- and critical-severity network attacks.

### **When Did the Network Attacks Occur?**

![Severity distribution of network attacks from August-October 2021 measured biweekly. During each period shown, high-severity attacks represent the largest proportion.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image.png) Figure 4. Attack severity distribution measured biweekly from August-October 2021.

For this installment of our network security trends analysis, we collected data from August-October 2021. Attackers steadily leveraged high-severity exploits throughout this period.

As we normally observe, attackers frequently used vulnerabilities disclosed recently, especially those from 2020-21. Attacks exploiting newly revealed vulnerabilities could be severe because of a late or improper patch. This highlights the importance of updating security products and applying software patches as soon as they become available to protect against the most recently discovered vulnerabilities.
![Observed network attacks broken down by the year in which the exploited CVE was disclosed, measured biweekly from August-October 2021. Vulnerabilities disclosed in 2020-2021 are shown in red. The oldest vulnerabilities, disclosed before 2010, are shown in dark blue.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-1.png) Figure 5. Observed attacks broken down by the year in which the exploited CVE was disclosed, measured biweekly from August-October 2021.

## **Exploits in the Wild, August-October 2021: A Detailed View**

We paid attention to the latest published attacks, and the following exploits stood out due to their PoC availability, severity and ease of exploitation. We have provided snippets showing how attackers used open-source tools to compromise the different targets to allow defenders to better understand how the exploit operates.

[CVE-2021-40438](https://nvd.nist.gov/vuln/detail/CVE-2021-40438)

Apache HTTP Server 2.4.48 and earlier has a server-side request forgery (SSRF) vulnerability via a crafted request URI-path which can cause mod\_proxy to forward the request to an origin server chosen by the remote user.
![Apache HTTP Server SSRF vulnerability - CVE-2021-40438](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-2.png) Figure 6. Apache HTTP Server SSRF vulnerability.

[CVE-2021-34473](https://nvd.nist.gov/vuln/detail/CVE-2021-34473)

Microsoft Exchange Server has an SSRF execution vulnerability that allows an attacker to bypass the authentication, impersonate an arbitrary user and write an arbitrary file to achieve remote code execution. By taking advantage of this vulnerability, the attacker can execute arbitrary commands on a remote Microsoft Exchange Server.
![Microsoft Exhange SSRF execution vulnerability - CVE-2021-34473 - case 1](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-3.png) Figure 7. Microsoft Exchange SSRF execution vulnerability case 1. ![Microsoft Exhange SSRF execution vulnerability - CVE-2021-34473 - case 2](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-4.png) Figure 8. Microsoft Exchange SSRF execution vulnerability case 2.

[CVE-2021-38647](https://nvd.nist.gov/vuln/detail/CVE-2021-38647)
![Microsoft OMI remote code execution vulnerability - CVE-2021-38647](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-5.png) Figure 9. Microsoft OMI remote code execution vulnerability.

By removing the authentication header, an attacker can issue an HTTP request to the Microsoft Open Management Infrastructure (OMI) management endpoint that will cause it to execute an operating system command as the root user.

[CVE-2021-26084](https://nvd.nist.gov/vuln/detail/CVE-2021-26084)

In affected versions of Confluence Server and Data Center, an Object-Graph Navigation Language (OGNL) injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
![Confluence Server OGNL injection RCE vulnerability - CVE-2021-26084](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-6.png) Figure 10. Confluence Server OGNL injection remote code execution vulnerability.

[CVE-2021-40870](https://nvd.nist.gov/vuln/detail/CVE-2021-40870)

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
![Aviatrix Controller directory traversal vulnerability - CVE-2021-40870](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-7.png) Figure 11. Aviatrix Controller directory traversal vulnerability.

[CVE-2021-33357](https://nvd.nist.gov/vuln/detail/CVE-2021-33357)

A vulnerability exists in RaspAP 2.6 to 2.6.5 in the iface GET parameter in /ajax/networking/get\_netcfg.php, when the iface parameter value contains special characters such as ; which enables an unauthenticated attacker to execute arbitrary OS commands.
![RaspAP remote command execution vulnerability - CVE-2021-33357](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-8.png) Figure 12. RaspAP remote command execution vulnerability.

[CVE-2021-35395](https://nvd.nist.gov/vuln/detail/CVE-2021-35395)

Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point.
![Realtek Jungle SDK Buffer overflow vulnerability - CVE-2021-35395](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-9.png) Figure 13. Realtek Jungle SDK buffer overflow vulnerability.

[CVE-2021-24499](https://nvd.nist.gov/vuln/detail/CVE-2021-24499)

The Workreap WordPress theme before 2.2.2 AJAX actions workreap\_award\_temp\_file\_uploader and workreap\_temp\_file\_uploader did not perform nonce checks or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.
![WordPress WorkReap file upload vulnerability - CVE-2021-24499](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-10.png) Figure 14. WordPress Workreap file upload vulnerability.

[CVE-2021-33766](https://nvd.nist.gov/vuln/detail/CVE-2021-33766)

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Exchange Server. By issuing a crafted request, an attacker can bypass authentication.
![Microsoft Exchange Server information disclosure vulnerability - CVE-2021-33766](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-11.png) Figure 15. Microsoft Exchange Server information disclosure vulnerability.

[CVE-2021-32789](https://nvd.nist.gov/vuln/detail/CVE-2021-32789)
![Automattic WooCommerce Blocks WordPress plugin store API SQL injection vulnerability - CVE-2021-32789](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-12.png) Figure 16. Automattic WooCommerce Blocks WordPress plugin store API SQL injection vulnerability.

woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the wc/store/products/collection-data?calculate\_attribute\_counts\[\]\[taxonomy\] endpoint that allows the execution of a read-only SQL query.

[CVE-2021-41773](https://nvd.nist.gov/vuln/detail/CVE-2021-41773), [CVE-2021-42013](https://nvd.nist.gov/vuln/detail/CVE-2021-42013)

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives.
![Apache HTTP server path traversal vulnerability - CVE-2021-41773, CVE-2021-42013](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-13.png) Figure 17. Apache HTTP server path traversal vulnerability.

### Attack Category Distribution

We classified each network attack by category and ranked them in Table 4 in order of prevalence. Information disclosure ranks first in this quarter, followed by code execution. Attackers typically want to gain as much information as they can and as much control as possible over the systems they target. Directory traversal attacks increased this quarter -- mature attack services and tools make it relatively simple for attackers to succeed with these types of exploits.

|-------------|----------------------------|
| **Ranking** | **Vulnerability Category** |
| 1           | Information Disclosure     |
| 2           | Code Execution             |
| 3           | Directory Traversal        |
| 4           | SQL Injection              |
| 5           | Command Injection          |
| 6           | Privilege Escalation       |
| 7           | Cross-Site Scripting       |
| 8           | Improper Authentication    |
| 9           | Security Feature Bypass    |
| 10          | Buffer Overflow            |

^*Table 4. Attack category ranking, August-October 2021.*^
![Category distribution for network attacks, August-October 2021. In order of prevalence, the categories are information disclosure, code execution, directory traversal, SQL injection, command injection, privilege escalation, cross-site scripting, improper authentication, security feature bypass, buffer overflow, denial of service](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/chart-3.png) Figure 18. Attack category distribution, August-October 2021.

### Where Did the Attacks Originate?

After identifying the region from which each network attack originated, we discovered that the largest number of them seem to originate from the United States, followed by China and Russia. However, we recognize that the attackers might leverage proxy servers and VPNs located in those countries to hide their actual physical locations.
![Locations ranked in terms of how frequently they were the origin of observed network attacks from August-October 2021: United States, China, Russian Federation, Netherlands, Luxembourg, India, Germany, United Kingdom, Korea, Canada, Singapore, Brazil, Panama, Indonesia, Belgium, France, Hong Kong, Turkey, Egypt, Ukraine, Others.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-14.png) Figure 19. Locations ranked in terms of how frequently they were the origin of observed attacks from August-October 2021. ![Attack geolocation distribution from August-October 2021. Lighter colors represent fewer attacks and darker colors show the opposite.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/12/word-image-15.png) Figure 20. Attack geolocation distribution from August-October 2021.

## **Conclusion**

The vulnerabilities published in August-October 2021 indicate that web applications remain popular targets for attackers, and that critical vulnerabilities are more likely to have PoCs publicly available. In the meantime, we continue to capture newly published vulnerabilities that are exploited in the wild. This emphasizes the need for organizations to promptly patch their systems and implement security best practices -- attackers will make a concerted effort to expand their arsenal of exploits whenever possible.

While cybercriminals will never cease their malicious activities, Palo Alto Networks customers are fully protected from the attacks discussed here by [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall). Additional mitigations include:

* Run a [Best Practice Assessment](https://www.paloaltonetworks.com/services/bpa) to identify where your configuration could be altered to improve your security posture.
* Continuously update your Next-Generation Firewalls with the latest Palo Alto Networks [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) content (e.g. versions 8487 and above).

## **Additional Resources**

* [Network Security Trends: May-July 2021](https://unit42.paloaltonetworks.com/network-security-trends/)
* [Network Attack Trends: February-April 2021](https://unit42.paloaltonetworks.com/network-attack-trends-february-april-2021/)
* [Network Attack Trends: November 2020-January 2021](https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/)
* [Network Attack Trends: August-October 2020](https://unit42.paloaltonetworks.com/network-attack-trends-internet-threats/)
* [Network Attack Trends: May-July 2020](https://unit42.paloaltonetworks.com/network-attack-trends/)

Back to top

### Tags

* [Attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/ "attack analysis")
* [Buffer Overflow](https://unit42.paloaltonetworks.com/tag/buffer-overflow/ "Buffer Overflow")
* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")
* [Cross-site request forgery](https://unit42.paloaltonetworks.com/tag/cross-site-request-forgery/ "cross-site request forgery")
* [Cross-site scripting](https://unit42.paloaltonetworks.com/tag/cross-site-scripting/ "cross-site scripting")
* [CVE-2021-24499](https://unit42.paloaltonetworks.com/tag/cve-2021-24499/ "CVE-2021-24499")
* [CVE-2021-26084](https://unit42.paloaltonetworks.com/tag/cve-2021-26084/ "CVE-2021-26084")
* [CVE-2021-32789](https://unit42.paloaltonetworks.com/tag/cve-2021-32789/ "CVE-2021-32789")
* [CVE-2021-33357](https://unit42.paloaltonetworks.com/tag/cve-2021-33357/ "CVE-2021-33357")
* [CVE-2021-33766](https://unit42.paloaltonetworks.com/tag/cve-2021-33766/ "CVE-2021-33766")
* [CVE-2021-34473](https://unit42.paloaltonetworks.com/tag/cve-2021-34473/ "CVE-2021-34473")
* [CVE-2021-35395](https://unit42.paloaltonetworks.com/tag/cve-2021-35395/ "CVE-2021-35395")
* [CVE-2021-38647](https://unit42.paloaltonetworks.com/tag/cve-2021-38647/ "CVE-2021-38647")
* [CVE-2021-40438](https://unit42.paloaltonetworks.com/tag/cve-2021-40438/ "CVE-2021-40438")
* [CVE-2021-40870](https://unit42.paloaltonetworks.com/tag/cve-2021-40870/ "CVE-2021-40870")
* [CVE-2021-41773](https://unit42.paloaltonetworks.com/tag/cve-2021-41773/ "CVE-2021-41773")
* [CVE-2021-42013](https://unit42.paloaltonetworks.com/tag/cve-2021-42013/ "CVE-2021-42013")
* [Denial of service](https://unit42.paloaltonetworks.com/tag/denial-of-service/ "denial of service")
* [Directory traversal](https://unit42.paloaltonetworks.com/tag/directory-traversal/ "directory traversal")
* [Exploit in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/ "exploit in the wild")
* [Improper authentication](https://unit42.paloaltonetworks.com/tag/improper-authentication/ "improper authentication")
* [Information disclosure](https://unit42.paloaltonetworks.com/tag/information-disclosure/ "information disclosure")
* [Memory corruption](https://unit42.paloaltonetworks.com/tag/memory-corruption/ "memory corruption")
* [Network security trends](https://unit42.paloaltonetworks.com/tag/network-security-trends/ "network security trends")
* [Out-of-bounds read](https://unit42.paloaltonetworks.com/tag/out-of-bounds-read/ "out-of-bounds read")
* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")
* [Remote Code Execution](https://unit42.paloaltonetworks.com/tag/remote-code-execution/ "Remote Code Execution")
* [Security feature bypass](https://unit42.paloaltonetworks.com/tag/security-feature-bypass/ "security feature bypass")
* [SQL injection](https://unit42.paloaltonetworks.com/tag/sql-injection/ "SQL injection")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)](https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/ "Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)")

### Table of Contents

* 

### Related Articles

* [Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "article - table of contents")
* [The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "article - table of contents")
* [Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
