CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats Aug 04, 2026

Hackers Exploiting Palo Alto's PAN-OS Vulnerability to Deploy Qilin Ransomware - CyberSecurityNews

CyberSecurityNews Archived Aug 04, 2026 ✓ Full text saved

Hackers Exploiting Palo Alto's PAN-OS Vulnerability to Deploy Qilin Ransomware CyberSecurityNews

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware By Guru Baran July 21, 2026 Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026, all tracing back to the same vulnerability as the initial point of entry. The flaw, tracked as CVE-2026-0257 (CVSS 7.8), affects the GlobalProtect portal and gateway in PAN-OS. It becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, allowing unauthenticated attackers to bypass login controls entirely and establish legitimate-looking VPN sessions. Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 (prior to specific patched builds), along with certain Prisma Access releases. Palo Alto Networks has confirmed limited active exploitation in the wild. In the intrusions Arctic Wolf reviewed, attackers used compromised VPN sessions to gain direct, interactive access to victim networks — completely skipping perimeter authentication. PAN-OS Vulnerability Exploited Once inside, attackers followed a fast-moving playbook: Established persistence using registry Run keys with a distinctive naming pattern (an asterisk plus six random lowercase letters) Deployed remote access tools like AnyDesk, Ngrok, and LogMeIn for redundant connectivity Dumped credentials from LSASS memory using rundll32.exe and comsvcs.dll, disguising output as a “.odt” file to evade detection Extracted the entire Active Directory database via ntdsutil.exe, gaining domain-wide credential access Used PsExec and administrative shares (C$) for lateral movement across the network Notably, several attacks originated from systems self-identifying with the hostname “kali,” and overlapping IP addresses appeared in both the initial exploitation and later VPN sessions, suggesting shared infrastructure or tooling among Qilin affiliates. While the entry point and core techniques remained stable, post-exploitation behavior varied significantly. Some intrusions moved straight to encryption with minimal dwell time, while others involved extensive reconnaissance, credential harvesting at scale, and data theft via Rclone to MEGA cloud storage before ransomware deployment. This variation is typical of ransomware-as-a-service (RaaS) operations, where different affiliates use shared tools but apply their own strategies. Before triggering encryption, attackers routinely disabled Microsoft Defender’s real-time protection and wiped Windows Event Logs using a PowerShell script that clears every log channel on the system, not just Security or System logs, making forensic recovery far harder. The ransomware payload itself, consistently named win.exe, was staged in C:\PerfLogs\, a default Windows directory rarely monitored by security tools. Execution required a password parameter, complicating sandbox analysis. Tactical Security Recommendations Arctic Wolf recommends immediate action: Patch CVE-2026-0257 across all internet-facing PAN-OS and Prisma Access deployments Terminate all active GlobalProtect sessions after patching Rotate all domain credentials, including the KRBTGT account, if exploitation is suspected Monitor and restrict execution from C:\PerfLogs Forward Windows Event Logs to a centralized SIEM to preserve evidence even if local logs are cleared Arctic Wolf assesses with moderate confidence that exploitation of this vulnerability leading to Qilin ransomware deployment is ongoing, driven by widespread scanning activity and the RaaS model’s tendency to distribute working exploits across multiple affiliates. The Privilege Paths Attackers See, That You Don’t: BeyondTrust Pathfinder Platform do it for You -> Get Free Identity Security Assessment Tags cyber security cyber security news Copy URL Linkedin Twitter ReddIt Telegram Guru Baranhttps://cybersecuritynews.com Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments. Cyber Security Guide Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory Top 10 Malware Used by Hackers Between July 20-26, 2026, to Launch Cyberattacks Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks Latest Cyber News Cyber Security DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data Cyber Security News Public PoC Released for Critical Rails Active Storage RCE Vulnerability Cyber Security Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models Cyber Security News TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks Cyber Security News Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild Expert Talks Cyber Security News CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources? Expert Talks How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict Expert Talks Why AI-generated identities mean verification can no longer be a one-time check
    💬 Team Notes
    Article Info
    Source
    CyberSecurityNews
    Category
    🛡 Active Threats
    Published
    Aug 04, 2026
    Archived
    Aug 04, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗