Qilin Ransomware Gang Exploits Critical Palo Alto VPN Flaw

The Qilin ransomware gang actively exploits a critical PAN-OS GlobalProtect authentication bypass vulnerability to breach corporate networks and deploy ransomware. The flaw, tracked as CVE-2026-0257, allows attackers to bypass security restrictions and establish unauthorized VPN connections on unpatched devices. Palo Alto Networks patched the vulnerability on May 13, but threat actors quickly began exploiting it just days later against numerous targets.

Arctic Wolf Labs reports investigating multiple intrusions during June 2026 that all originate from exploitation of this vulnerability against Palo Alto firewall appliances. These attacks result in domain-wide Qilin ransomware encryption, with post-exploitation tactics ranging from rapid encryption-only operations to full double-extortion campaigns. This variation suggests multiple affiliates operate under the Qilin ransomware-as-a-service umbrella.

The U.S. Cybersecurity and Infrastructure Security Agency adds the flaw to its Known Exploited Vulnerability catalog and orders federal agencies to secure their GlobalProtect VPN instances within three days. Shadowserver currently tracks over 167,000 GlobalProtect VPN instances exposed online, highlighting the massive attack surface. Arctic Wolf assesses with moderate confidence that these intrusions likely continue as scanning activity remains extensive across vulnerable systems.

Read More at the original source →