Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks

Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks

Posted on July 21, 2026 By CWS

Cybersecurity experts have identified an active exploitation of a critical flaw in Palo Alto Networks firewalls, enabling cybercriminals to infiltrate corporate networks and deploy the Qilin ransomware. This alarming discovery was highlighted in recent research conducted by Arctic Wolf Labs.

Understanding the PAN-OS Vulnerability

The vulnerability, cataloged as CVE-2026-0257 with a CVSS score of 7.8, affects the GlobalProtect portal and gateway in PAN-OS. This flaw becomes a significant concern when authentication override cookies are used in conjunction with particular certificate setups. Such a configuration allows attackers to completely bypass login controls, establishing seemingly legitimate VPN sessions without authentication.

Versions impacted include PAN-OS 12.1, 11.2, 11.1, and 10.2 before certain patched builds, alongside specific releases of Prisma Access. Palo Alto Networks has acknowledged limited but active exploitation instances.

Exploitation Tactics and Methods

During the intrusions analyzed by Arctic Wolf, attackers leveraged compromised VPN sessions to directly access victim networks, bypassing perimeter authentication. Once inside, they executed a swift and systematic strategy to maintain control.

The attackers established persistence by using registry Run keys with uniquely patterned names. They utilized remote access tools such as AnyDesk, Ngrok, and LogMeIn to ensure ongoing connectivity. Credential dumping from LSASS memory was disguised as a ‘.odt’ file to avoid detection, and the entire Active Directory database was extracted for comprehensive domain access.

Post-Exploitation Activities and Countermeasures

Post-infiltration, the tactics varied greatly. Some attackers rapidly initiated encryption, while others focused on reconnaissance, large-scale credential harvesting, and data theft. This diversity is characteristic of ransomware-as-a-service (RaaS) models, where affiliates share tools but customize their attack strategies.

To mitigate these threats, Arctic Wolf recommends immediate patching of the CVE-2026-0257 vulnerability across all PAN-OS and Prisma Access deployments. Terminating all active GlobalProtect sessions post-patching, rotating domain credentials, and monitoring unusual executions from the C:PerfLogs directory are crucial steps in enhancing security.

Finally, forwarding Windows Event Logs to a centralized SIEM is advised to preserve critical evidence, even if local logs are manipulated or erased. Arctic Wolf’s analysis indicates that exploitation of this flaw, linked to Qilin ransomware attacks, is an ongoing risk driven by broad scanning activities and the RaaS framework’s exploitation distribution.

Strengthening your Security Operations Center (SOC) with accelerated threat detection and response capabilities is essential in combating these evolving cyber threats. Integrating tools like ANY.RUN can significantly enhance your SOC’s efficiency and effectiveness.

Cyber Security News Tags:Arctic Wolf Labs, authentication bypass, credential theft, CVE-2026-0257, Cybersecurity, data breach, firewall security, network security, PAN-OS, Qilin ransomware, Ransomware deployment, ransomware-as-a-service, remote access tools, threat detection, vulnerability patching

Post navigation

Previous Post: Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
Next Post: Furtex: Advanced Linux Toolkit for Security Experts

Related Posts

PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild Cyber Security News
Microsoft 365 Services and Copilot Outage Hits Users in Japan and China Microsoft 365 Services and Copilot Outage Hits Users in Japan and China Cyber Security News
AzureHound Penetration Testing Tool Exploited by Threat Actors to Enumerate Azure and Entra ID AzureHound Penetration Testing Tool Exploited by Threat Actors to Enumerate Azure and Entra ID Cyber Security News
Oblivion RAT: New Android Threat with Hidden Control Oblivion RAT: New Android Threat with Hidden Control Cyber Security News
Urgent Patch for QNAP QVR Pro Security Flaw Released Urgent Patch for QNAP QVR Pro Security Flaw Released Cyber Security News
Critical Microsoft Edge Flaw Enables Remote Code Execution Critical Microsoft Edge Flaw Enables Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark