Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

Qilin ransomware exploits Palo Alto VPN flaw in June attacks

1 min
Qilin ransomware exploits Palo Alto VPN flaw in June attacks

This digest was compiled by AI from multiple sources — links to the originals are below.

Arctic Wolf Labs warns that cybercriminals exploited a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks GlobalProtect portal and gateway to deploy Qilin ransomware in June. The attacks occurred within days of disclosure, with post-exploitation tactics ranging from rapid encryption to double extortion, suggesting multiple affiliates under the Qilin RaaS umbrella.

The Vulnerability

The flaw, CVE-2026-0257, is an authentication bypass in Palo Alto GlobalProtect portal and gateway. Arctic Wolf Labs identified it as the common link in a series of intrusions in June. Exploitation began within days of disclosure, highlighting the speed at which ransomware groups weaponize new vulnerabilities.

Qilin's Broader Campaign

Qilin was the most active threat group in Q2 2026, responsible for 14% of attacks, according to NCC Group's Quarterly Cyber Threat Intelligence Report. Beyond Palo Alto, Qilin has targeted flaws in Fortinet FortiGate, Citrix NetScaler, and Check Point Remote Access VPN. The group's tactics vary, with some intrusions involving rapid encryption and others full double extortion.

Rising Edge Device Threats

Ransomware groups are increasingly targeting vulnerabilities in network edge devices. The Gentlemen, No. 2 on NCC Group's list with 238 victims in Q2 2026, exploits FortiGate and Cisco products. Akira, No. 4 with 127 victims, targets Ivanti, Cisco, and Fortinet VPNs. Matt Hull of NCC Group noted that while ransomware volume hasn't risen materially, the trajectory of attacks continues upward, with VPNs remaining an attractive target.

1 source

Time · lag behind first