HackMyIP
← Back to News
2026-07-21 The Hacker News

Qilin Ransomware Exploits PAN-OS Authentication Bypass Vulnerability

RansomwareVulnerabilityAuthentication

Threat actors affiliated with the Qilin (also known as Agenda) ransomware-as-a-service (RaaS) operation have been weaponizing a now-patched high-severity flaw in Palo Alto Networks PAN-OS to gain initial access to enterprise environments. According to Arctic Wolf Labs, multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass vulnerability carrying a CVSS score of 7.8. The flaw resides in the portal and gateway components of PAN-OS and allows unauthenticated remote attackers to sidestep authentication and establish SSL VPN sessions without valid credentials when authentication override cookies are enabled alongside specific certificate configurations. Organizations concerned about exposed VPN infrastructure can audit their public-facing attack surface using the port scanner to identify unpatched management interfaces.

Once authenticated access was secured through the SSL VPN session, the attackers escalated their operations by harvesting credentials and moving laterally through Windows administrative shares via compromised administrative accounts. The threat actors staged their ransomware payloads in C:\PerfLogs\, used PsExec for lateral execution, and deployed password-protected binaries to evade detection. Before launching encryption routines, they deliberately cleared Windows event logs and disabled Microsoft Defender Real-Time Protection, demonstrating a clear focus on minimizing forensic evidence. A distinctive Windows Registry persistence pattern was also observed, consisting of an asterisk followed by six randomized lowercase alphabetic characters. Security teams can validate their endpoint hardening and credential hygiene using the password checker to identify weak or compromised administrative passwords.

Although core tradecraft elements remained consistent, follow-on attack methodologies varied significantly across victims, consistent with a multi-affiliate RaaS model. Some incidents involved rapid, enterprise-wide encryption with no data theft, while others featured extensive reconnaissance using remote access tools such as AnyDesk, Ngrok, and LogMeIn. In the most damaging cases, attackers conducted large-scale credential theft and exfiltrated sensitive data to the MEGA cloud service using Rclone, Proton Drive, and FileZilla prior to ransomware deployment, executing a full double-extortion playbook. Given the SSL VPN trust implications of this vulnerability, administrators should verify their appliance certificates and tunnel configurations with the SSL/TLS checker to ensure no residual exposure remains from the authentication override feature.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →