ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Qilin ransomware gains entry via Palo Alto PAN-OS authentication bypass (CVE-2026-0257)

Source headline: Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 4 hours ago

Intelligence Summary

Threat actors have used a patched Palo Alto Networks PAN-OS authentication bypass to reach victim networks. The initial access flaw, CVE-2026-0257, affects the device portal and gateway. After exploiting the weakness, intruders deploy Qilin (also known as Agenda) ransomware. Arctic Wolf Labs reported multiple June 2026 intrusions that followed this pattern. Organizations running vulnerable PAN-OS versions should ensure updates are applied and monitor for related compromise indicators.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#ransomware #qilin #authentication-bypass #pan-os #agenda #cve-2026-0257
Original reporting The Hacker News Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Open original source