Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Chronological Source Flow
Back

AI Fusion Summary

Qilin ransomware operators, also known as Agenda, are exploiting a high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect. Arctic Wolf Labs investigated multiple intrusions in June 2026 involving CVE-2026-0257, which has a CVSS score of 7.8. This flaw affects the portal and gateway, allowing unauthorized access to enterprise VPN infrastructure. This activity marks a shift in tradecraft, moving from phishing and supply chain tactics toward direct exploitation of VPN systems.
Community Comments
Loading updates...
0