Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
ID: 28f6ce23-c976-58b3-b532-24aef297d269
STIX ID: report--28f6ce23-c976-58b3-b532-24aef297d269
Feed Name: The Hacker News
**Active exploitation of PAN-OS CVE-2026-0257 leads to Qilin/Agenda ransomware intrusions:** Arctic Wolf Labs investigated multiple June 2026 intrusions where attackers bypassed authentication to create SSL VPN sessions, escalated to credential harvesting and lateral movement (PsExec, administrative shares), staged ransomware at C:\PerfLogs, disabled Defender and cleared logs, and in some cases exfiltrated data to MEGA using tools like Rclone before encryption — behaviors consistent with a ransomware-as-a-service affiliate model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
