logo

Critical Palo Alto VPN Bug Now Exploited by Qilin Ransomware Gang

ID: 0910c4c8-41b8-5264-8837-647763e22b8b

STIX ID: report--0910c4c8-41b8-5264-8837-647763e22b8b

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

**Qilin ransomware group is actively exploiting a critical authentication-bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect to gain unauthenticated access and deploy cross-platform ransomware (including ESXi targeting and double-extortion).** The report, citing Arctic Wolf confirmation of in-the-wild exploitation, outlines the vulnerability details, attack chain, detection signals, and urgent mitigations such as immediate patching, log review for indicators of compromise, restricting management interfaces, and enabling threat prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.