Arctic Wolf Labs investigated multiple intrusions during June 2026 where threat actors exploited CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain initial access and deploy Qilin ransomware. After establishing VPN sessions, attackers performed credential harvesting via LSASS dumping and NTDS extraction, moved laterally using PsExec and administrative shares, deployed multiple remote access tools for persistence, and executed enterprise-wide log clearing before ransomware deployment. The variability in post-exploitation tradecraft across intrusions is consistent with multiple affiliates operating under the Qilin RaaS umbrella sharing exploitation infrastructure.
CVE-2026-0257
3 posts
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257 Arctic Wolf Labs observed an ongoing campaign exploiting CVE-2026-0257, a high-severity authentication bypass vulnerability in Palo Alto Networks GlobalProtect. Threat actors are forging authentication override cookies to establish unauthorized VPN sessions, followed by rapid internal network reconnaissance using Impacket tooling.
1st June – Threat Intelligence Report This threat intelligence bulletin highlights a surge in data breaches driven by social engineering, alongside the increasing weaponization of AI tools for phishing, malware development, and supply chain attacks. Active exploitation of vulnerabilities in PAN-OS GlobalProtect and Ghost CMS has been observed, while a critical unpatched RCE in Gogs remains a significant risk. Additionally, targeted campaigns like Grandoreiro and JINX-0164 continue to threaten the financial and cryptocurrency sectors using platform-specific malware and DLL side-loading.