IN June 2026, Arctic Wolf Labs identified multiple ransomware incidents linked to the Qilin ransomware, attributed to an exploitation of the CVE-2026-0257 vulnerability in Palo Alto Networks' GlobalProtect firewall. This authentication bypass allowed attackers to gain VPN access without valid credentials, leading to domain-wide encryption of data. The Qilin operation employs a ransomware-as-a-service model with evidence suggesting multiple affiliates are involved.
Victims faced not only encryption but also data exfiltration in double-extortion cases. No arrests have been reported, and ongoing exploitation is expected. Recommendations for protection include updating affected systems, monitoring suspicious VPN sessions, and recognizing early signs of intrusion to prevent encryption.