Skip to content

Qilin Ransomware Exploits Critical Palo Alto VPN Vulnerability for Network Intrusions

Bottom line: VPN devices from Palo Alto, Fortinet, Citrix and Check Point are being systematically exploited by ransomware groups because they provide direct network access and are frequently unpatched.

Cybercriminals are exploiting a critical authentication vulnerability (CVE-2026-0257) in Palo Alto GlobalProtect to deploy the Qilin ransomware. Multiple ransomware groups are increasingly targeting vulnerable VPNs and edge devices as preferred attack vectors.

Arctic Wolf Labs documented a series of intrusions in June in which the authentication vulnerability CVE-2026-0257 in Palo Alto GlobalProtect Portal and Gateway played a central role. Exploitation began days after the security advisory was published. Post-exploitation techniques varied: from rapid encryption-only operations to full double-extortion, suggesting multiple affiliate operators operating under the Qilin RaaS umbrella.

According to the NCC Group Q2 2026 report, Qilin was the most active threat group with 14% of all incidents. In addition to GlobalProtect, the group has also exploited vulnerabilities in Fortinet FortiGate, Citrix NetScaler and Check Point Remote Access VPN. Check Point warned in June of attacks on VPNs still using the outdated IKEv1 protocol. Citrix released patches in July for a CitrixBleed-like flaw in NetScaler devices. In June, the Fortibleed campaign exposed 75,000 FortiGate firewalls through credential compromise.

Qilin is not an isolated case: The Gentlemen (ranked 2nd, 238 victims in Q2 2026) prefers intrusions via firewalls and VPNs, particularly FortiGate and Cisco products. Akira (ranked 4th, 127 victims) exploits VPN vulnerabilities and abuses legitimate credentials, primarily targeting Ivanti, Cisco and Fortinet.

Network edge security devices are increasingly becoming security risks for enterprise decision-makers. A sharp rise in zero-day exploits shows that many of these vulnerabilities are fundamental and preventable. A broad spectrum of actors — from opportunistic hackers to RaaS operators and state-sponsored APT groups — are actively exploiting software vulnerabilities.

VPNs are attractive to attackers because they provide direct access to the enterprise network. They can gain entry through unpatched vulnerabilities, stolen credentials or weak authentication. The path through edge devices significantly shortens the detection window — security teams often have little time to apply vendor patches before exploitation begins.


Source: www.csoonline.com · Published July 24, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: