Palo Alto Networks revealed a critical vulnerability (CVE-2025-0108) in PAN-OS that allows unauthenticated attackers to bypass authentication via the management web interface. This flaw, caused by path confusion between Nginx and Apache, exposes systems to significant risks, enabling unauthorized access to sensitive PHP scripts. Users are advised to upgrade to patched versions and restrict interface access.
![](https://healsecurity.com/wp-content/uploads/2025/01/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it.jpg)
Threat actors are leaning on trusted services more than ever
Researchers have observed that cyber threats are now using legitimate services as part of their attack strategy. This trend highlights the growing complexity and sophistication