IOC Radar
TLP:WHITE4 IOCs

THREAT ADVISORY Palo Alto Firewall Zero-Day May 7, 2026

BC
Blackswan Cybersecurity
Published May 7, 2026Original Report

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE146.70.100.69http://146.70.100.69:…CAPABILITYunknownVICTIMunknown
Adversary
Infrastructure(2)
Capability
Victim

Attack Flow7 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/7
Exploit Public-Facing Application
ActionExploit firewall vulnerability
Unauthenticated remote code execution via a buffer overflow vulnerability in the Captive Portal service of PAN-OS.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise4

TypeIndicatorConfidenceScoreFirst Seen
IP146.70.100.69
intel-blognetworkproxy
High
58
Jun 2, 26
CVECVE-2026-0300
aptespionageexploit
High
62
Jun 2, 26
SHA256e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584
file-hashintel-blogproxy
Medium
53
Jun 2, 26
URLhttp://146.70.100.69:8000/php_sess
intel-blognetworkproxy
High
58
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph4 total IOCs
IPCVESHA256URL
IP1CVE1SHA2561URL1REPORTTHREAT ADVISORY Palo Alto
scroll to zoom · drag to pan · click IOC to open