CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2883

As cited

Copy frozen at (site build).

ransomware

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect to gain initial access to target networks. Arctic Wolf researchers documented this threat actor leveraging the flaw as part of their attack chain.

Why it matters: Organizations using Palo Alto GlobalProtect VPN are at immediate risk of compromise by a known ransomware operator; patching this critical flaw should be prioritized if not already completed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks (PAN) OS GlobalProtect to gain initial access to victim networks, according to Arctic Wolf. This represents a shift from the group's typical attack patterns and demonstrates rapid weaponization of the vulnerability in the wild.

Why it matters: Organizations running PAN-OS GlobalProtect are at immediate risk of network compromise by Qilin; patching this critical flaw should be a top priority.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks (PAN) OS GlobalProtect to gain initial access to victim networks, according to Arctic Wolf. This represents a shift from the group's typical attack patterns and demonstrates rapid weaponization of the vulnerability in the wild.

Why it matters: Organizations running PAN-OS GlobalProtect are at immediate risk of network compromise by Qilin; patching this critical flaw should be a top priority.

VendorsPalo Alto Networks
Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary