Wire · founder news, decoded · technology
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
◆ Published
21 July 2026
◆ Topic
technology
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
Qilin ransomware operators are exploiting CVE-2026-0257, a high-severity Palo Alto Networks PAN-OS authentication bypass, to gain initial access to victim networks and deploy encryption payloads. Arctic Wolf Labs documented multiple intrusions in June 2026 using the flaw to sidestep VPN authentication when specific certificate configurations are present.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you run a Palo Alto perimeter gateway with certificate-based VPN, your authentication is bypassed right now unless you've patched. Check your logs for anomalous VPN sessions dating back to June—that's your entry point if you've been hit.
◆ Related on Wire
- VPN service favored by ransomware groups is sanctioned by US14 July 2026
- U.S. Hits Ransomware Supply Chain With New Sanctions15 July 2026
- US Sanctions First VPN in Crackdown on Ransomware Criminals16 July 2026
- U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support14 July 2026
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks ...14 July 2026
- Hackers are Actively Exploiting ServiceNow Vulnerability in the wild22 July 2026
◆ Topics
Cybersecurity · pan-os-cve-2026-0257 · qilin-ransomware · vpn-bypass · zero-trust · incident-response