Cybersecurity 2 h agoAdd to bookmarks

A critical authentication bypass vulnerability in PAN-OS on the GlobalProtect portal (Palo Alto Networks' VPN firewall) is now being exploited in the real world by the Qilin ransomware gang. Arctic Wolf, relayed by BleepingComputer, confirms active intrusions: the patch can no longer wait.
BleepingComputer reports, based on observations from Arctic Wolf, that the cybercriminal group Qilin (ransomware-as-a-service active since 2022, known for its attacks on healthcare and retail) is now exploiting a critical authentication bypass vulnerability in PAN-OS, on the GlobalProtect portal side of Palo Alto Networks - that is, in the firewall/portal firmware exposed, not on the end client side. The observed intrusions aim to deploy Qilin's in-house ransomware in the victim networks.
Three cumulative elements:
We are seeing the classic scenario of the VPN edge device turned into an intrusion highway - as we saw with Ivanti, Fortinet, Citrix in recent years. Qilin is part of a growing trend: RaaS gangs quickly buy (or develop) exploits for edge devices, precisely because the window between the publication of the advisory and the deployment of the patch in the enterprise remains much too wide. Treating a PAN-OS firewall like an ordinary application server - patched within 72 hours, with monitoring on it - is no longer optional.
Article produced by artificial intelligence, reviewed under human editorial control.