Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Qilin Ransomware Exploits PAN-OS Vulnerability for Access

Qilin Ransomware Exploits PAN-OS Vulnerability for Access

Posted on July 21, 2026 By CWS

In a recent cybersecurity development, attackers have been leveraging a critical flaw in Palo Alto Networks’ PAN-OS to distribute the Qilin ransomware, also known as Agenda. The vulnerability, which has since been patched, served as a gateway for malicious actors to infiltrate victim systems.

Details of the Exploited Vulnerability

Arctic Wolf Labs discovered that the attacks in June 2026 began by targeting CVE-2026-0257, a high-severity authentication bypass issue in the PAN-OS software’s portal and gateway components. This vulnerability, with a CVSS score of 7.8, allowed attackers to bypass authentication mechanisms and initiate VPN sessions without valid credentials, especially when certain certificate configurations were used.

The exploitation of this flaw enabled attackers to execute a range of operations, from rapid encryption to double extortion tactics. These variations suggest the involvement of multiple affiliates within the Qilin ransomware-as-a-service (RaaS) framework.

Attack Techniques and Patterns

Despite the diversity in execution methods, a consistent pattern emerged among the intrusions. Attackers typically staged ransomware at C:PerfLogs, utilized PsExec for lateral movements across administrative shares, deployed password-protected ransomware payloads, and systematically cleared logs to evade detection.

The attackers exploited the vulnerability to gain authenticated network access, establishing SSL VPN sessions and escalating their attacks to harvest credentials and move laterally through compromised Windows administrative shares.

Impact and Implications

To minimize detection risks, the attackers proactively cleared event logs and disabled Microsoft Defender’s real-time protection before executing the ransomware. This strategy was part of a broader effort to reduce forensic evidence and complicate recovery efforts.

The attacks exhibited variability, with some targeting enterprise-wide encryption without data theft, while others involved detailed reconnaissance and credential theft using tools such as AnyDesk, Ngrok, and LogMeIn. Data exfiltration was also noted in some cases, utilizing services like MEGA, Rclone, Proton Drive, and FileZilla prior to ransomware deployment.

As noted by Arctic Wolf, such variability aligns with RaaS models, where multiple affiliates share initial access methods but apply distinct post-exploitation techniques. This highlights the adaptive and multifaceted nature of modern ransomware operations.

The continued exploitation of security flaws underscores the need for robust cybersecurity measures and timely patch management to mitigate the risks posed by sophisticated threat actors.

The Hacker News Tags:Arctic Wolf, authentication bypass, credential theft, CVE-2026-0257, Cybersecurity, data exfiltration, log clearing, Microsoft Defender, network security, PAN-OS vulnerability, PsExec, Qilin ransomware, RaaS, SSL-VPN, Threat Actors

Post navigation

Previous Post: Microsoft to End Copilot Podcasts in 2026
Next Post: SecurityWeek Unveils Critical Impact Awards for Cybersecurity

Related Posts

F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion The Hacker News
Coinbase Agents Bribed, Data of ~1% Users Leaked; M Extortion Attempt Fails Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails The Hacker News
Dashlane Alerts Users of Recent Security Breach Dashlane Alerts Users of Recent Security Breach The Hacker News
Microsoft Detects “SesameOp” Backdoor Using OpenAI’s API as a Stealth Command Channel Microsoft Detects “SesameOp” Backdoor Using OpenAI’s API as a Stealth Command Channel The Hacker News
Man-in-the-Middle Attack Prevention Guide Man-in-the-Middle Attack Prevention Guide The Hacker News
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark