Start with Identity
← Blog
News

Qilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door

Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session without valid credentials when authentication override cookies are misconfigured.

By SWI Community TeamJul 21, 2026Updated Aug 6, 2026

Arctic Wolf Labs documented multiple intrusions in June 2026 in which Qilin (also tracked as Agenda) ransomware affiliates gained initial access by exploiting CVE-2026-0257 (CVSS 7.8), a now-patched flaw in Palo Alto Networks PAN-OS portal and gateway components. The bug lets an unauthenticated remote attacker sidestep authentication entirely and establish a working VPN session without valid credentials, when authentication override cookies are enabled alongside specific certificate configurations. Post-exploitation tactics varied across the intrusions Arctic Wolf reviewed, from fast encryption-only runs to full double-extortion campaigns with data exfiltration, a pattern consistent with multiple ransomware-as-a-service affiliates using the same entry point independently. Common tradecraft included staging payloads in C:\PerfLogs, PsExec for lateral movement, password-protected payloads, and log clearing.

Why it matters

An authentication bypass on a VPN gateway is worse than a stolen credential in one specific way: there's no compromised account to disable, no password to rotate, because the attacker never needed one. That's what makes it a clean initial-access vector for multiple unaffiliated ransomware crews to reuse against the same unpatched population.

If you run PAN-OS with authentication override cookies enabled, patching alone doesn't tell you whether you were already hit in the window before the fix; check for the staging and lateral-movement pattern Arctic Wolf documented, not just patch status.

Source: The Hacker News

Independent analysis. No vendor sponsorship.