Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Qilin Ransomware Exploits PAN-OS Vulnerability for Access

Qilin Ransomware Exploits PAN-OS Vulnerability for Access

Posted on July 21, 2026 By CWS

In a recent cybersecurity development, attackers have been leveraging a critical flaw in Palo Alto Networks’ PAN-OS to distribute the Qilin ransomware, also known as Agenda. The vulnerability, which has since been patched, served as a gateway for malicious actors to infiltrate victim systems.

Details of the Exploited Vulnerability

Arctic Wolf Labs discovered that the attacks in June 2026 began by targeting CVE-2026-0257, a high-severity authentication bypass issue in the PAN-OS software’s portal and gateway components. This vulnerability, with a CVSS score of 7.8, allowed attackers to bypass authentication mechanisms and initiate VPN sessions without valid credentials, especially when certain certificate configurations were used.

The exploitation of this flaw enabled attackers to execute a range of operations, from rapid encryption to double extortion tactics. These variations suggest the involvement of multiple affiliates within the Qilin ransomware-as-a-service (RaaS) framework.

Attack Techniques and Patterns

Despite the diversity in execution methods, a consistent pattern emerged among the intrusions. Attackers typically staged ransomware at C:PerfLogs, utilized PsExec for lateral movements across administrative shares, deployed password-protected ransomware payloads, and systematically cleared logs to evade detection.

The attackers exploited the vulnerability to gain authenticated network access, establishing SSL VPN sessions and escalating their attacks to harvest credentials and move laterally through compromised Windows administrative shares.

Impact and Implications

To minimize detection risks, the attackers proactively cleared event logs and disabled Microsoft Defender’s real-time protection before executing the ransomware. This strategy was part of a broader effort to reduce forensic evidence and complicate recovery efforts.

The attacks exhibited variability, with some targeting enterprise-wide encryption without data theft, while others involved detailed reconnaissance and credential theft using tools such as AnyDesk, Ngrok, and LogMeIn. Data exfiltration was also noted in some cases, utilizing services like MEGA, Rclone, Proton Drive, and FileZilla prior to ransomware deployment.

As noted by Arctic Wolf, such variability aligns with RaaS models, where multiple affiliates share initial access methods but apply distinct post-exploitation techniques. This highlights the adaptive and multifaceted nature of modern ransomware operations.

The continued exploitation of security flaws underscores the need for robust cybersecurity measures and timely patch management to mitigate the risks posed by sophisticated threat actors.

The Hacker News Tags:Arctic Wolf, authentication bypass, credential theft, CVE-2026-0257, Cybersecurity, data exfiltration, log clearing, Microsoft Defender, network security, PAN-OS vulnerability, PsExec, Qilin ransomware, RaaS, SSL-VPN, Threat Actors

Post navigation

Previous Post: Microsoft to End Copilot Podcasts in 2026
Next Post: SecurityWeek Unveils Critical Impact Awards for Cybersecurity

Related Posts

Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server The Hacker News
Crypto Malware Campaign Exploits Fake Reviews and AI Crypto Malware Campaign Exploits Fake Reviews and AI The Hacker News
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets The Hacker News
Critical Cisco Unified CM Flaw Actively Exploited Critical Cisco Unified CM Flaw Actively Exploited The Hacker News
Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack The Hacker News
NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark