Bleepingcomputer
Qilin Ransomware Gang Exploits Critical Palo Alto VPN Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' GlobalProtect VPN. Discovered by Arctic Wolf Labs, the flaw allows attackers to bypass security measures and establish unauthorized VPN connections. The vulnerability was published on May 13, 2026, and was added to the CISA's Known Exploited Vulnerability catalog on May 29, 2026. Since then, multiple intrusions have been reported, leading to domain-wide ransomware encryption. Arctic Wolf noted that these attacks have been ongoing, with evidence of multiple affiliates within the Qilin Ransomware-as-a-Service (RaaS) model. Over 167,000 GlobalProtect VPN instances are exposed online, increasing the risk of exploitation. High-profile victims include organizations across various sectors, highlighting the widespread impact of this vulnerability.
Key Points: • Qilin ransomware gang exploits CVE-2026-0257 in Palo Alto VPNs. • Over 167,000 GlobalProtect VPN instances are exposed online. • Multiple high-profile organizations have been targeted in these attacks.