HIGHRansomware
Global

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

·Source: The Hacker News

Updated:

Executive Summary

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

Analysis

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

Indicators of Compromise (1)

CVE (1)
CVE-2026-0257
Source Attribution

Originally published by The Hacker News on Jul 21, 2026.

Related Threats