← BACK TO FEED
TAG

palo alto networks3 articles

China Opens Security Probe Into Palo Alto Networks — And Tells Us Absolutely Nothing About Why

China's Cyberspace Administration (CAC) has launched a security review of Palo Alto Networks' products, citing the need to protect critical infrastructure and national security, though no further details have been provided. The probe mirrors a similar 2023 investigation into Micron, which ultimately resulted in the memory-maker being effectively banned from selling to Chinese critical infrastructure operators, costing it billions in revenue. Analysts suggest the review could be used to favour domestic competitors such as Huawei and H3C, while Palo Alto has stated there is currently no impact on its operations or customers in the region.

7 Aug 2026

AI Hallucination Brands Startup as Chinese Spy Operation. No One Checked.

MeetingTV has sued Palo Alto Networks and its newly acquired Koi Security after Koi published a threat intelligence report falsely linking the video conferencing startup to a Chinese corporate espionage operation. MeetingTV alleges the report was generated by Koi's AI platform, which hallucinated connections between the startup and a criminal threat actor called DarkSpectre, including referencing a browser extension that MeetingTV claims does not exist. The false report caused widespread domain blocks by security providers globally, severely damaging MeetingTV's business, and the startup's CEO has warned the case highlights the dangers of publishing AI-generated findings without adequate human oversight.

3 Jul 2026

Palo Alto's GlobalProtect Flaw Was Being Actively Exploited Within Days of Disclosure

A high-severity authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect portal and gateway was patched on May 13, but threat actors began actively exploiting it just four days after public disclosure. Rapid7 observed multiple waves of attacks across customer environments, with attackers using forged cookies to bypass authentication and, in some cases, gain access to internal networks via VPN. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and is urging federal agencies to apply the available patches by June 1.

1 Jun 2026