Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

Threat actors associated with the Qilin ransomware, also known as Agenda, have reportedly leveraged a high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS as an initial access vector into victim networks. Security researchers at Arctic Wolf Labs observed multiple intrusions in June 2026 where the exploitation of this specific flaw marked the starting point of the attack chain, culminating in the deployment of Qilin ransomware.
The vulnerability, identified as CVE-2026-0257, carries a CVSS score of 7.8, indicating its significant severity. It is described as an authentication bypass flaw that impacts the portal and gateway components of PAN-OS. Such bypasses typically allow an unauthenticated attacker to circumvent security controls designed to verify user identity, potentially gaining unauthorized access to sensitive system functions or data.
In this specific scenario, the authentication bypass in the PAN-OS portal and gateway likely provided the attackers with a foothold. The portal and gateway are critical components for remote access and network segmentation in many enterprise environments, making them attractive targets for initial compromise. Once inside, the threat actors could then proceed with their attack objectives, which in these observed cases involved the deployment of the Qilin ransomware.
Qilin ransomware, like many modern ransomware variants, typically encrypts files on compromised systems and demands a ransom payment for their decryption. The initial access gained through the PAN-OS vulnerability would have allowed the attackers to establish persistence, move laterally within the network, and ultimately execute the ransomware payload across a broader set of systems.
Palo Alto Networks has since released patches to address CVE-2026-0257. Organizations utilizing affected versions of PAN-OS are strongly advised to apply these security updates immediately to mitigate the risk of exploitation. Furthermore, implementing multi-factor authentication (MFA) on all remote access points, including VPNs and administrative interfaces, can significantly reduce the impact of authentication bypass vulnerabilities, even if they are exploited.
Beyond patching, organizations should also focus on robust network segmentation, endpoint detection and response (EDR) solutions, and regular security audits to detect and prevent post-exploitation activities. This class of attack underscores the critical importance of promptly patching internet-facing network infrastructure devices, as they often serve as the first line of defense against sophisticated threat actors.
The exploitation of a high-severity vulnerability in widely deployed network security products for initial access to deploy ransomware is a recurring theme in the cybersecurity landscape. This incident highlights the ongoing challenge for organizations to maintain a proactive patching posture and implement defense-in-depth strategies to protect against evolving ransomware threats and the sophisticated tactics employed by groups like those behind Qilin.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a