GlobalProtect actively exploited: Qilin exploits Palo Alto VPN

Cybersecurity 7 h agoAdd to bookmarks

GlobalProtect actively exploited: Qilin exploits Palo Alto VPN
Illustration : Momiji Shirogane

A critical authentication bypass vulnerability in PAN-OS on the GlobalProtect portal (Palo Alto Networks' VPN firewall) is now being exploited in the real world by the Qilin ransomware gang. Arctic Wolf, relayed by BleepingComputer, confirms active intrusions: the patch can no longer wait.

The facts

BleepingComputer reports, based on observations from Arctic Wolf, that the cybercriminal group Qilin (ransomware-as-a-service active since 2022, known for its attacks on healthcare and retail) is now exploiting a critical authentication bypass vulnerability in PAN-OS, on the GlobalProtect portal side of Palo Alto Networks - that is, in the firewall/portal firmware exposed, not on the end client side. The observed intrusions aim to deploy Qilin's in-house ransomware in the victim networks.

Who is affected

  • Organizations that expose the GlobalProtect portal (Palo Alto firewall for remote access) on the Internet - that is, the vast majority of PAN-OS deployments providing VPN.
  • Maximum priority for high-value targets: hospitals, law firms, industry, local authorities - Qilin's usual modus operandi.

What makes the matter serious

Three cumulative elements:

  1. Active exploitation - we have moved from the theoretical (advisory) to the observation of successful intrusions documented by Arctic Wolf.
  2. Compromised perimeter firewall - a compromised PAN-OS portal is direct access to the internal network via a trusted edge device, not just a simple user workstation.
  3. Chaining to ransomware - the exploitation is not used to spy discreetly, it is used to encrypt and ransom. The reaction window is measured in hours.

What to do now

  • Check the PAN-OS version of all exposed GlobalProtect portals and immediately apply the corresponding Palo Alto patch for the current advisory (see security.paloaltonetworks.com).
  • Hunt for IoCs published by Arctic Wolf and the threat intel teams tracking Qilin.
  • Audit accounts that have used the VPN during the exposure window: abnormal sessions, creation of local accounts, unexpected PowerShell execution.
  • Isolate any host contacted from the VPN portal with suspicious lateral behavior (SMB, WinRM, internal RDP).

Analysis

We are seeing the classic scenario of the VPN edge device turned into an intrusion highway - as we saw with Ivanti, Fortinet, Citrix in recent years. Qilin is part of a growing trend: RaaS gangs quickly buy (or develop) exploits for edge devices, precisely because the window between the publication of the advisory and the deployment of the patch in the enterprise remains much too wide. Treating a PAN-OS firewall like an ordinary application server - patched within 72 hours, with monitoring on it - is no longer optional.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

24 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information