Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking
Incidents: Chinese state-linked actors exploit Palo Alto firewall zero-day (CVE-2026-0300) for RCE and covert network access.
Deep Analysis and Expert Commentary
The exploitation of CVE-2026-0300 demonstrates a calculated attack path: initial shellcode injection via Nginx worker processes, followed by immediate log destruction to hinder forensic analysis. Attackers then pivot to AD reconnaissance using firewall service accounts, suggesting intent for lateral movement. The use of open-source tools (Earthworm, ReverseSocks5) aligns with Chinese APT tradecraft, blending in with legitimate traffic. Affected organizations must prioritize patching PA/VM series firewalls by May 13/28 or implement Palo Alto's interim mitigations (disabling User-ID agent or enabling strict source IP validation). Network defenders should hunt for unexpected outbound tunneling traffic and scrutinize AD service account activity, particularly targeting DomainDnsZones.
Action Items
- Apply Palo Alto's interim mitigations (disable User-ID agent or enforce source IP validation) immediately.
- Monitor for Earthworm/ReverseSocks5 tunneling traffic on non-standard ports.
- Audit firewall service account permissions and DomainDnsZones access patterns.
Original Article Brief Intro
SecurityWeek · 2026-05-07 · Incidents: Chinese state-linked actors exploit Palo Alto firewall zero-day (CVE-2026-0300) for RCE and covert network access.
Related Terms and Notes
CVE IDs
- CVE-2026-0300 — Critical RCE flaw in Palo Alto firewalls' User-ID portal allowing root access without authentication.
Malware Families
- Earthworm — Open-source network tunneling tool frequently used by Chinese APTs for covert C2 communications.
Techniques / TTPs
- RCE
- Zero-Day
- Zero-Day Exploit
Context Notes
- APT
- Cyber Espionage
- Firewall
- Network Security
- Palo Alto
- State-Sponsored Hacking