INTEL_REPORT
Palo Alto Networks Unit 42 · published 7/17/2026, 10:00:24 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 . Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research …
https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities
sha256:751679cfdfa24cc34ab35241bd67dea769b1990157be4be2c15cee8a805c526f
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| cve | CVE-2025-14847 | Open → |
| cve | CVE-2025-23304 | Open → |
| cve | CVE-2026-22584 | Open → |
| cve | CVE-2025-40949 | Open → |
| cve | CVE-2025-40947 | Open → |
| cve | CVE-2025-40948 | Open → |
| cve | CVE-2026-0257 | Open → |