Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks

Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks

Posted on July 21, 2026 By CWS

Cybersecurity experts have identified an active exploitation of a critical flaw in Palo Alto Networks firewalls, enabling cybercriminals to infiltrate corporate networks and deploy the Qilin ransomware. This alarming discovery was highlighted in recent research conducted by Arctic Wolf Labs.

Understanding the PAN-OS Vulnerability

The vulnerability, cataloged as CVE-2026-0257 with a CVSS score of 7.8, affects the GlobalProtect portal and gateway in PAN-OS. This flaw becomes a significant concern when authentication override cookies are used in conjunction with particular certificate setups. Such a configuration allows attackers to completely bypass login controls, establishing seemingly legitimate VPN sessions without authentication.

Versions impacted include PAN-OS 12.1, 11.2, 11.1, and 10.2 before certain patched builds, alongside specific releases of Prisma Access. Palo Alto Networks has acknowledged limited but active exploitation instances.

Exploitation Tactics and Methods

During the intrusions analyzed by Arctic Wolf, attackers leveraged compromised VPN sessions to directly access victim networks, bypassing perimeter authentication. Once inside, they executed a swift and systematic strategy to maintain control.

The attackers established persistence by using registry Run keys with uniquely patterned names. They utilized remote access tools such as AnyDesk, Ngrok, and LogMeIn to ensure ongoing connectivity. Credential dumping from LSASS memory was disguised as a ‘.odt’ file to avoid detection, and the entire Active Directory database was extracted for comprehensive domain access.

Post-Exploitation Activities and Countermeasures

Post-infiltration, the tactics varied greatly. Some attackers rapidly initiated encryption, while others focused on reconnaissance, large-scale credential harvesting, and data theft. This diversity is characteristic of ransomware-as-a-service (RaaS) models, where affiliates share tools but customize their attack strategies.

To mitigate these threats, Arctic Wolf recommends immediate patching of the CVE-2026-0257 vulnerability across all PAN-OS and Prisma Access deployments. Terminating all active GlobalProtect sessions post-patching, rotating domain credentials, and monitoring unusual executions from the C:PerfLogs directory are crucial steps in enhancing security.

Finally, forwarding Windows Event Logs to a centralized SIEM is advised to preserve critical evidence, even if local logs are manipulated or erased. Arctic Wolf’s analysis indicates that exploitation of this flaw, linked to Qilin ransomware attacks, is an ongoing risk driven by broad scanning activities and the RaaS framework’s exploitation distribution.

Strengthening your Security Operations Center (SOC) with accelerated threat detection and response capabilities is essential in combating these evolving cyber threats. Integrating tools like ANY.RUN can significantly enhance your SOC’s efficiency and effectiveness.

Cyber Security News Tags:Arctic Wolf Labs, authentication bypass, credential theft, CVE-2026-0257, Cybersecurity, data breach, firewall security, network security, PAN-OS, Qilin ransomware, Ransomware deployment, ransomware-as-a-service, remote access tools, threat detection, vulnerability patching

Post navigation

Previous Post: Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
Next Post: Furtex: Advanced Linux Toolkit for Security Experts

Related Posts

Choosing the Right Tool for Network Penetration Testing Choosing the Right Tool for Network Penetration Testing Cyber Security News
Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS Cyber Security News
Ubiquiti Releases Critical Updates for UniFi OS Vulnerabilities Ubiquiti Releases Critical Updates for UniFi OS Vulnerabilities Cyber Security News
Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns Cyber Security News
New Windows Attack Method Evades Leading Security Tools New Windows Attack Method Evades Leading Security Tools Cyber Security News
Weaponized Putty and Teams Ads Deliver Malware Allowing Hackers to Access Network Weaponized Putty and Teams Ads Deliver Malware Allowing Hackers to Access Network Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark