logo

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

ID: 44790fb1-1a9b-5c11-a21f-0195304b8bf7

STIX ID: report--44790fb1-1a9b-5c11-a21f-0195304b8bf7

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Pierluigi Paganini

...
...

Qilin ransomware affiliates are actively exploiting the critical PAN-OS GlobalProtect authentication bypass CVE-2026-0257 to establish unauthorized VPN sessions on unpatched Palo Alto Networks appliances, enabling initial access that leads to credential theft, lateral movement (PsExec, RDP), persistence (registry Run keys, scheduled tasks), data exfiltration (Rclone, cloud storage) and deployment of Qilin ransomware with both encryption-only and double-extortion outcomes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.