Particle.news
Download on the App Store

Qilin Ransomware Exploits Palo Alto GlobalProtect Authentication Bypass

The flaw lets unauthenticated attackers open VPN sessions that give direct network access, leaving many exposed GlobalProtect appliances vulnerable.

Overview

  • Palo Alto released a patch for CVE-2026-0257 on May 13 and the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerability catalog on May 29.
  • Researchers say the bug lets attackers bypass GlobalProtect login checks to establish SSL VPN sessions without credentials, which they then use to harvest accounts and move laterally across networks.
  • Arctic Wolf investigated multiple intrusions in June that began with the GlobalProtect bypass and led to Qilin (Agenda) ransomware, and the firm assesses with moderate confidence that affiliate-driven exploitation is likely ongoing.
  • Observed attacker methods include staging ransomware in C:\PerfLogs, using PsExec over Windows admin shares, disabling Microsoft Defender, clearing logs, and sometimes exfiltrating data to cloud services before encryption.
  • Internet scans show roughly 167,000–172,000 GlobalProtect fingerprints exposed online, so organizations should apply patches, force VPN re-authentication, check logs for anomalous VPN sessions, enable layered access controls, and assume unpatched appliances may already be compromised.