Qilin ransomware group exploiting critical Palo Alto Networks PAN-OS authentication bypass
The Qilin ransomware gang is actively leveraging a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN to gain unauthorized network access. While the specific scope of victim impact remains unquantified, the exploitation of this flaw represents a significant escalation in threat actor capabilities against enterprise infrastructure.
Score Breakdown
Part of 2 situations
Qilin Ransomware Activity Escalates with PAN-OS Exploitation and Increased Attacks
The Qilin ransomware group has escalated its activity, leading global cyber incidents with 24 claimed attacks for the week of July 15-21, 2026, primarily targeting US government and military sectors. This increased activity is concurrent with confirmed exploitation of a critical Palo Alto Networks PAN-OS authentication bypass vulnerability to gain network access. The total volume of compromised data is claimed to be 29.6 TB, though attribution relies on self-reported claims.