← Back

Wire · technology

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Published

21 July 2026

Topic

technology

Sectors

Cybersecurity

Source

Read at thehackernews.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

Qilin ransomware operators are exploiting CVE-2026-0257, a high-severity Palo Alto Networks PAN-OS authentication bypass, to gain initial access to victim networks and deploy encryption payloads. Arctic Wolf Labs documented multiple intrusions in June 2026 using the flaw to sidestep VPN authentication when specific certificate configurations are present.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you run a Palo Alto perimeter gateway with certificate-based VPN, your authentication is bypassed right now unless you've patched. Check your logs for anomalous VPN sessions dating back to June—that's your entry point if you've been hit.

Coverage

1 source · 21 Jul 2026

Related on Wire

Topics

Cybersecuritypan-os-cve-2026-0257qilin-ransomwarevpn-bypasszero-trustincident-response