THE Qilin ransomware group is exploiting a critical vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS that allows attackers to bypass VPN authentication on GlobalProtect portals and gateways. This vulnerability was patched by Palo Alto on May 13, 2026, but was actively being exploited shortly thereafter.
Arctic Wolf Labs reported multiple instances where the Qilin ransomware was deployed after accessing corporate networks through this flaw, highlighting the urgency for organizations to apply security updates. The attackers utilized a variety of tactics, including credential theft and establishing unauthorized VPN sessions, to facilitate their operations, which often included data encryption and theft. The Qilin group has been particularly active in targeting various sectors and collaborates with other ransomware groups to enhance attack effectiveness.