LIVE · cybersecurity feed
Live wire
CVE-2026-0257high

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

zeroday.news · 11d ago

Threat actors associated with the Qilin ransomware, also known as Agenda, have reportedly leveraged a high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS as an initial access vector into victim networks. Security researchers at Arctic Wolf Labs observed multiple intrusions in June 2026 where the exploitation of this specific flaw marked the starting point of the attack chain, culminating in the deployment of Qilin ransomware.

The vulnerability, identified as CVE-2026-0257, carries a CVSS score of 7.8, indicating its significant severity. It is described as an authentication bypass flaw that impacts the portal and gateway components of PAN-OS. Such bypasses typically allow an unauthenticated attacker to circumvent security controls designed to verify user identity, potentially gaining unauthorized access to sensitive system functions or data.

In this specific scenario, the authentication bypass in the PAN-OS portal and gateway likely provided the attackers with a foothold. The portal and gateway are critical components for remote access and network segmentation in many enterprise environments, making them attractive targets for initial compromise. Once inside, the threat actors could then proceed with their attack objectives, which in these observed cases involved the deployment of the Qilin ransomware.

Qilin ransomware, like many modern ransomware variants, typically encrypts files on compromised systems and demands a ransom payment for their decryption. The initial access gained through the PAN-OS vulnerability would have allowed the attackers to establish persistence, move laterally within the network, and ultimately execute the ransomware payload across a broader set of systems.

Palo Alto Networks has since released patches to address CVE-2026-0257. Organizations utilizing affected versions of PAN-OS are strongly advised to apply these security updates immediately to mitigate the risk of exploitation. Furthermore, implementing multi-factor authentication (MFA) on all remote access points, including VPNs and administrative interfaces, can significantly reduce the impact of authentication bypass vulnerabilities, even if they are exploited.

Beyond patching, organizations should also focus on robust network segmentation, endpoint detection and response (EDR) solutions, and regular security audits to detect and prevent post-exploitation activities. This class of attack underscores the critical importance of promptly patching internet-facing network infrastructure devices, as they often serve as the first line of defense against sophisticated threat actors.

The exploitation of a high-severity vulnerability in widely deployed network security products for initial access to deploy ransomware is a recurring theme in the cybersecurity landscape. This incident highlights the ongoing challenge for organizations to maintain a proactive patching posture and implement defense-in-depth strategies to protect against evolving ransomware threats and the sophisticated tactics employed by groups like those behind Qilin.

ransomwarevulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.