Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
By Dillip Chowdary β’ Jul 21, 2026 β’ Source: BleepingComputer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is actively exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf, as reported by BleepingComputer. The flaw sits in Palo Alto Networks' GlobalProtect VPN surface and allows attackers to bypass authentication rather than brute-force or phish credentials. Arctic Wolf's attribution places a known ransomware operator behind live abuse of the bug, not just proof-of-concept chatter or opportunistic scanning.
Technically, an authentication bypass on GlobalProtect means an attacker can reach the protected edge without presenting valid user credentials. GlobalProtect is the VPN gateway many enterprises use to expose internal apps and network segments to remote staff. Once that gate is skipped, the operator can treat the VPN as an entry point into the corporate network and stage further ransomware activity from inside. The critical severity label reflects that the defect breaks the primary trust check on a perimeter system that is often internet-facing by design.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders who run PAN-OS GlobalProtect, this is a direct network-edge risk: ransomware crews favor VPN and remote-access flaws because they deliver authenticated-looking access without endpoint malware first. If GlobalProtect is in production, the authentication bypass becomes a single control failure that can collapse the assumption that only legitimate remote users sit behind the tunnel. That matters for anyone responsible for identity-aware access, network segmentation, and incident response playbooks that still treat VPN login as a strong trust signal.
In the broader market, ransomware groups have repeatedly targeted edge appliances and VPN products from major vendors because those boxes concentrate access and are hard to rotate quickly. Qilin joining the set of actors abusing this class of PAN-OS GlobalProtect defect fits that pattern: high-value edge software, public-facing exposure, and a flaw that removes the need for stolen credentials. Defenders comparing vendor risk should treat active ransomware exploitation as a higher priority than unattributed scanning alone.
Practical takeaway: confirm whether PAN-OS GlobalProtect is exposed in your estate, apply Palo Alto's remediation guidance for the critical authentication bypass without delay, and review VPN and authentication logs for anomalous pre-auth or post-bypass activity consistent with edge compromise. Watch Arctic Wolf and vendor advisories for indicators of compromise and any expansion of Qilin's targeting beyond the cases already described. Until the gateway is patched or taken offline, treat internet-facing GlobalProtect as an active ransomware entry path rather than a routine remote-access service.
Advertisement