top of page
ALL POSTS
Qilin Ransomware Operators Exploit CVE-2026-0257 Palo Alto GlobalProtect Vulnerability for VPN Compromise
Key Findings Arctic Wolf Labs identified multiple June 2026 intrusions where attackers exploited CVE-2026-0257 to deliver Qilin ransomware across victim domains CVE-2026-0257 is an authentication bypass in Palo Alto Networks GlobalProtect affecting PAN-OS versions 10.2, 11.1, 11.2, and 12.1, plus some Prisma Access deployments Attackers gained VPN access without credentials, then moved laterally to steal credentials and deploy ransomware, with some cases involving double exto
Jul 212 min read
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Bypass Flaw (CVE-2026-0257)
Key Findings CVE-2026-0257 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS affecting GlobalProtect portals and gateways Active exploitation confirmed by Rapid7 starting May 17, 2026, with two distinct attack waves originating from different hosting providers Vulnerability allows attackers to forge authentication cookies and bypass VPN access controls without credentials CISA added the flaw to its Known Exploited Vulnerabilities catalog in early June, re
Jun 153 min read
Palo Alto Networks Fixes GlobalProtect Flaw Allowing Unauthenticated Denial of Service
Key Findings Palo Alto Networks addressed a high-severity vulnerability, tracked as CVE-2026-0227 (CVSS score: 7.7), affecting GlobalProtect Gateway and Portal. A proof-of-concept (PoC) exploit for the vulnerability exists. The flaw allows an unauthenticated attacker to cause a denial-of-service (DoS) condition that can force the firewall into maintenance mode, disrupting network traffic and firewall protection. The vulnerability affects multiple versions of Palo Alto Network
Jan 152 min read
bottom of page
