Bleepingcomputer
Qilin Ransomware Gang Exploits Critical Palo Alto VPN Vulnerability
Article Content
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect VPN software. This flaw allows attackers to bypass security restrictions and establish unauthorized VPN connections. Palo Alto Networks issued a patch for the vulnerability on May 13, 2026, but exploitation attempts were reported starting May 17. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerability catalog on May 29, mandating federal agencies to secure their systems. Arctic Wolf Labs has documented multiple intrusions leading to Qilin ransomware deployment, indicating ongoing exploitation. Over 167,000 GlobalProtect VPN instances are exposed online, raising concerns about widespread vulnerability. The Qilin ransomware operation has claimed over 2,000 victims since its inception in 2022, affecting high-profile organizations across various sectors.
Key Points: • CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto's GlobalProtect. • The Qilin ransomware gang is exploiting this flaw to breach corporate networks and deploy ransomware. • Over 167,000 GlobalProtect VPN instances remain exposed, increasing the risk of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.