Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
ID: 44790fb1-1a9b-5c11-a21f-0195304b8bf7
STIX ID: report--44790fb1-1a9b-5c11-a21f-0195304b8bf7
Feed Name: Security Affairs
Threat Score
Qilin ransomware affiliates are actively exploiting the critical PAN-OS GlobalProtect authentication bypass CVE-2026-0257 to establish unauthorized VPN sessions on unpatched Palo Alto Networks appliances, enabling initial access that leads to credential theft, lateral movement (PsExec, RDP), persistence (registry Run keys, scheduled tasks), data exfiltration (Rclone, cloud storage) and deployment of Qilin ransomware with both encryption-only and double-extortion outcomes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
