Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Reported exploitedPAN-OSQilin Ransomware GroupOur summary
Threat actors are actively exploiting a recently patched vulnerability in Palo Alto Networks' PAN-OS software to gain unauthorized access and deploy the Qilin ransomware. The flaw, CVE-2026-0257, allows attackers to bypass authentication and establish SSL VPN sessions when certain certificate configurations are enabled. Arctic Wolf Labs reported multiple incidents in June 2026 where this vulnerability was leveraged as an initial access vector, leading to varied post-exploitation tactics including encryption and data exfiltration. Affected systems should apply available patches immediately.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.