logo

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

ID: ad856266-28e6-5304-b124-866b848ba7cd

STIX ID: report--ad856266-28e6-5304-b124-866b848ba7cd

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Sergiu Gatlan

...
...

Arctic Wolf reports that Qilin ransomware affiliates are actively exploiting a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to establish unauthorized VPN access and deploy ransomware, with multiple incidents in June 2026 leading to domain-wide encryption; CISA has listed the flaw in its Known Exploited Vulnerability catalog, and internet scans show hundreds of thousands of exposed GlobalProtect instances, increasing the risk of further compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.