
Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access
Threat actors deploying Qilin ransomware exploited a Palo Alto Networks GlobalProtect authentication bypass flaw, CVE-2026-0257, as the consistent initial access vector across multiple June 2026 intrusions investigated by Arctic Wolf Labs. The campaign moved rapidly from perimeter compromise to domain-wide encryption, with post-exploitation tactics varying between affiliates operating under Qilin’s ransomware-as-a-service model. CVE-2026-0257 (CVSS 7.8) […]
The post Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access appeared first on Cyber Security News.