Home / Jul 22, 2026 / Story
0
#3 The Hacker News general July 21, 2026 at 14:04 UTC

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

By [email protected] (The Hacker News)

AI Summary

Arctic Wolf Labs confirmed that Qilin (aka Agenda) ransomware operators exploited CVE-2026-0257 (CVSS 7.8), a Palo Alto Networks PAN-OS authentication bypass affecting GlobalProtect portal and gateway, in multiple intrusions during June 2026. This is a significant escalation, as a high-severity VPN perimeter flaw is now being used as initial access for ransomware deployment at scale.

Relevance score: 89.0/100

# More from July 22