Qilin ransomware gang exploits critical Palo Alto flaw

 

Qilin ransomware gang exploits critical Palo Alto flaw

The Qilin ransomware gang is exploiting a critical security flaw in Palo Alto Networks' PAN-OS GlobalProtect software to break into company networks and deploy ransomware.

The vulnerability, tracked as CVE-2026-0257, was fixed by Palo Alto Networks on May 13. However, researchers reported that attackers began exploiting the flaw just days later. Cybersecurity company Arctic Wolf said it investigated several attacks during June 2026 where the vulnerability was used to gain access before Qilin ransomware was deployed.

According to Arctic Wolf, the attacks varied in how they were carried out. Some victims experienced ransomware encryption, while others faced double-extortion attacks, where data was stolen before systems were locked. The company believes multiple Qilin affiliates are actively using the flaw and warns that the attacks are likely still ongoing.

Qilin is a Ransomware-as-a-Service (RaaS) operation that first appeared in 2022 under the name ‘Agenda.’ Since then, it has claimed more than 2,000 victims on its dark web leak site. Organizations reportedly affected by Qilin include Nissan, Yangfeng, Asahi, Synnovis, Lee Enterprises, and Australia's Court Services Victoria.


Back to the list