Qilin ransomware group exploiting critical Palo Alto Networks PAN-OS authentication bypass
The Qilin ransomware gang is actively leveraging a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN to gain unauthorized network access. While the specific scope of victim impact remains unquantified, the exploitation of this flaw represents a significant escalation in threat actor capabilities against enterprise infrastructure.
Score Breakdown
Part of 2 situations
Qilin Ransomware Activity Escalates with PAN-OS Exploitation and Increased Attacks
The Qilin ransomware group has escalated its activity, leading global cyber incidents with 24 claimed attacks during the week of July 15-21, 2026. This surge is concurrent with confirmed exploitation of a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN, enabling unauthorized network access. The full scope of victim impact from this vulnerability exploitation remains unquantified.