logo

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

ID: 28f6ce23-c976-58b3-b532-24aef297d269

STIX ID: report--28f6ce23-c976-58b3-b532-24aef297d269

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

**Active exploitation of PAN-OS CVE-2026-0257 leads to Qilin/Agenda ransomware intrusions:** Arctic Wolf Labs investigated multiple June 2026 intrusions where attackers bypassed authentication to create SSL VPN sessions, escalated to credential harvesting and lateral movement (PsExec, administrative shares), staged ransomware at C:\PerfLogs, disabled Defender and cleared logs, and in some cases exfiltrated data to MEGA using tools like Rclone before encryption — behaviors consistent with a ransomware-as-a-service affiliate model.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.