Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks

Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks

Posted on July 21, 2026 By CWS

Cybersecurity experts have identified an active exploitation of a critical flaw in Palo Alto Networks firewalls, enabling cybercriminals to infiltrate corporate networks and deploy the Qilin ransomware. This alarming discovery was highlighted in recent research conducted by Arctic Wolf Labs.

Understanding the PAN-OS Vulnerability

The vulnerability, cataloged as CVE-2026-0257 with a CVSS score of 7.8, affects the GlobalProtect portal and gateway in PAN-OS. This flaw becomes a significant concern when authentication override cookies are used in conjunction with particular certificate setups. Such a configuration allows attackers to completely bypass login controls, establishing seemingly legitimate VPN sessions without authentication.

Versions impacted include PAN-OS 12.1, 11.2, 11.1, and 10.2 before certain patched builds, alongside specific releases of Prisma Access. Palo Alto Networks has acknowledged limited but active exploitation instances.

Exploitation Tactics and Methods

During the intrusions analyzed by Arctic Wolf, attackers leveraged compromised VPN sessions to directly access victim networks, bypassing perimeter authentication. Once inside, they executed a swift and systematic strategy to maintain control.

The attackers established persistence by using registry Run keys with uniquely patterned names. They utilized remote access tools such as AnyDesk, Ngrok, and LogMeIn to ensure ongoing connectivity. Credential dumping from LSASS memory was disguised as a ‘.odt’ file to avoid detection, and the entire Active Directory database was extracted for comprehensive domain access.

Post-Exploitation Activities and Countermeasures

Post-infiltration, the tactics varied greatly. Some attackers rapidly initiated encryption, while others focused on reconnaissance, large-scale credential harvesting, and data theft. This diversity is characteristic of ransomware-as-a-service (RaaS) models, where affiliates share tools but customize their attack strategies.

To mitigate these threats, Arctic Wolf recommends immediate patching of the CVE-2026-0257 vulnerability across all PAN-OS and Prisma Access deployments. Terminating all active GlobalProtect sessions post-patching, rotating domain credentials, and monitoring unusual executions from the C:PerfLogs directory are crucial steps in enhancing security.

Finally, forwarding Windows Event Logs to a centralized SIEM is advised to preserve critical evidence, even if local logs are manipulated or erased. Arctic Wolf’s analysis indicates that exploitation of this flaw, linked to Qilin ransomware attacks, is an ongoing risk driven by broad scanning activities and the RaaS framework’s exploitation distribution.

Strengthening your Security Operations Center (SOC) with accelerated threat detection and response capabilities is essential in combating these evolving cyber threats. Integrating tools like ANY.RUN can significantly enhance your SOC’s efficiency and effectiveness.

Cyber Security News Tags:Arctic Wolf Labs, authentication bypass, credential theft, CVE-2026-0257, Cybersecurity, data breach, firewall security, network security, PAN-OS, Qilin ransomware, Ransomware deployment, ransomware-as-a-service, remote access tools, threat detection, vulnerability patching

Post navigation

Previous Post: Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
Next Post: Furtex: Advanced Linux Toolkit for Security Experts

Related Posts

Microsoft Entra Passkey Enrollment Exploited by Hackers Microsoft Entra Passkey Enrollment Exploited by Hackers Cyber Security News
Dell Vulnerability Exploited by Chinese Hackers Since 2024 Dell Vulnerability Exploited by Chinese Hackers Since 2024 Cyber Security News
Allianz Life Insurance Data Breach Allianz Life Insurance Data Breach Cyber Security News
Critical VMware Aria Flaws Enable Remote Code Attacks Critical VMware Aria Flaws Enable Remote Code Attacks Cyber Security News
Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild Cyber Security News
Microsoft Confirms New Outlook Bug Blocking Excel Attachments Microsoft Confirms New Outlook Bug Blocking Excel Attachments Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark