CyberHighConfirmedAccelerating
10.0
Qilin ransomware group exploiting critical Palo Alto Networks PAN-OS authentication bypass
BleepingComputer·US·about 11 hours ago
Global cyber activity reached 350 incidents across 58 countries, with the U.S. government and military sectors remaining the primary targets. Qilin emerged as the most active threat actor, contributing to a total of 29.6 TB of compromised data, though the attribution relies on self-reported claims by threat actors.
Entities
The Qilin ransomware group has escalated its activity, leading global cyber incidents with 24 claimed attacks during the week of July 15-21, 2026. This surge is concurrent with confirmed exploitation of a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN, enabling unauthorized network access. The full scope of victim impact from this vulnerability exploitation remains unquantified.