Skip to content

Qilin Ransomware Exploits Critical Palo Alto GlobalProtect Vulnerability for Network Access

Bottom line: Qilin ransomware exploits a critical authentication vulnerability in Palo Alto GlobalProtect VPN to gain direct network access.

The ransomware group Qilin is abusing a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect to infiltrate networks. Arctic Wolf has documented these active exploits in attack scenarios.

According to security firm Arctic Wolf, the ransomware group Qilin is deliberately exploiting a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect. The Virtual Private Network (VPN) module GlobalProtect is frequently the first access point to enterprise internal networks and is therefore a preferred attack target.

Exploiting this security vulnerability enables Qilin to authenticate VPN-protected systems and thereby gain access to internal network segments. This typically forms the basis for downstream ransomware deployments and lateral movement within compromised infrastructure.

For CISOs, this means immediate action is required: affected Palo Alto environments require immediate patches, network monitoring of the VPN access layer, and review of access logs for suspicious authentication activity. The fact that an established ransomware group is operationally exploiting this vulnerability indicates a transition into the active exploitation phase.


Source: www.bleepingcomputer.com · Published July 21, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: