Qilin ransomware affiliates are actively exploiting the PAN-OS GlobalProtect authentication bypass flaw, CVE-2026-0257, to gain unauthorized VPN access and deploy domain-wide encryption against victim networks. Arctic Wolf says the intrusions are ongoing and may involve multiple Qilin affiliates using both encryption-only and double-extortion tactics. #Qilin #PAN-OS #GlobalProtect #CVE-2026-0257
Keypoints
- Palo Alto Networks patched CVE-2026-0257 on May 13.
- Attackers began exploiting the flaw soon after the fix.
- Arctic Wolf linked multiple June 2026 intrusions to Qilin.
- The attacks led to domain-wide ransomware encryption.
- More than 167,000 GlobalProtect VPN instances are exposed online.