Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Qilin Ransomware Exploits PAN-OS Vulnerability for Access

Qilin Ransomware Exploits PAN-OS Vulnerability for Access

Posted on July 21, 2026 By CWS

In a recent cybersecurity development, attackers have been leveraging a critical flaw in Palo Alto Networks’ PAN-OS to distribute the Qilin ransomware, also known as Agenda. The vulnerability, which has since been patched, served as a gateway for malicious actors to infiltrate victim systems.

Details of the Exploited Vulnerability

Arctic Wolf Labs discovered that the attacks in June 2026 began by targeting CVE-2026-0257, a high-severity authentication bypass issue in the PAN-OS software’s portal and gateway components. This vulnerability, with a CVSS score of 7.8, allowed attackers to bypass authentication mechanisms and initiate VPN sessions without valid credentials, especially when certain certificate configurations were used.

The exploitation of this flaw enabled attackers to execute a range of operations, from rapid encryption to double extortion tactics. These variations suggest the involvement of multiple affiliates within the Qilin ransomware-as-a-service (RaaS) framework.

Attack Techniques and Patterns

Despite the diversity in execution methods, a consistent pattern emerged among the intrusions. Attackers typically staged ransomware at C:PerfLogs, utilized PsExec for lateral movements across administrative shares, deployed password-protected ransomware payloads, and systematically cleared logs to evade detection.

The attackers exploited the vulnerability to gain authenticated network access, establishing SSL VPN sessions and escalating their attacks to harvest credentials and move laterally through compromised Windows administrative shares.

Impact and Implications

To minimize detection risks, the attackers proactively cleared event logs and disabled Microsoft Defender’s real-time protection before executing the ransomware. This strategy was part of a broader effort to reduce forensic evidence and complicate recovery efforts.

The attacks exhibited variability, with some targeting enterprise-wide encryption without data theft, while others involved detailed reconnaissance and credential theft using tools such as AnyDesk, Ngrok, and LogMeIn. Data exfiltration was also noted in some cases, utilizing services like MEGA, Rclone, Proton Drive, and FileZilla prior to ransomware deployment.

As noted by Arctic Wolf, such variability aligns with RaaS models, where multiple affiliates share initial access methods but apply distinct post-exploitation techniques. This highlights the adaptive and multifaceted nature of modern ransomware operations.

The continued exploitation of security flaws underscores the need for robust cybersecurity measures and timely patch management to mitigate the risks posed by sophisticated threat actors.

The Hacker News Tags:Arctic Wolf, authentication bypass, credential theft, CVE-2026-0257, Cybersecurity, data exfiltration, log clearing, Microsoft Defender, network security, PAN-OS vulnerability, PsExec, Qilin ransomware, RaaS, SSL-VPN, Threat Actors

Post navigation

Previous Post: Microsoft to End Copilot Podcasts in 2026
Next Post: SecurityWeek Unveils Critical Impact Awards for Cybersecurity

Related Posts

Enhance SOC Efficiency with Three Key Process Improvements Enhance SOC Efficiency with Three Key Process Improvements The Hacker News
nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery The Hacker News
Linux Kernel Vulnerability Allows Root Access Exploit Linux Kernel Vulnerability Allows Root Access Exploit The Hacker News
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs The Hacker News
North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers The Hacker News
Meta Expands WhatsApp Security Research with New Proxy Tool and M in Bounties This Year Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This Year The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark