importantSYS.SOURCE: The Hacker News• 2026-07-21T19:34:57+05:30
Qilin Ransomware Leverages PAN-OS Authentication Bypass for Network Infiltration
Threat actors are exploiting a patched PAN-OS authentication bypass vulnerability (CVE-2026-0257) to gain initial access and deploy Qilin ransomware. The attack involves lateral movement, credential harvesting, and log-clearing tactics, with variations in post-exploitation methods across different affiliates.
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
*** END OF TRANSMISSION ***