top of page
ALL POSTS
Qilin Ransomware Operators Exploit CVE-2026-0257 Palo Alto GlobalProtect Vulnerability for VPN Compromise
Key Findings Arctic Wolf Labs identified multiple June 2026 intrusions where attackers exploited CVE-2026-0257 to deliver Qilin ransomware across victim domains CVE-2026-0257 is an authentication bypass in Palo Alto Networks GlobalProtect affecting PAN-OS versions 10.2, 11.1, 11.2, and 12.1, plus some Prisma Access deployments Attackers gained VPN access without credentials, then moved laterally to steal credentials and deploy ransomware, with some cases involving double exto
Jul 212 min read
Hugging Face Hit by Autonomous AI Agent in Major Security Breach
Key Findings Hugging Face disclosed a production breach on July 16, 2024, executed entirely by an autonomous AI agent Attackers exploited two code-execution vulnerabilities in the data-processing pipeline using a malicious dataset Internal datasets and service credentials were exposed; no tampering detected in public models, datasets, or Spaces The AI agent performed thousands of actions across short-lived sandboxes, escalating from worker-level to node-level access and movin
Jul 183 min read
bottom of page
