Somewhere there's a corporate network still running unpatched Palo Alto VPN gear, blissfully unaware that its front door has had a "push to enter, no key required" sign on it since May. The Qilin ransomware crew found that sign months ago.
A Cookie That Bypasses the Whole Guard Station
CVE-2026-0257 is an authentication bypass in PAN-OS's GlobalProtect portal and gateway, letting attackers establish full VPN sessions with zero valid credentials when authentication override cookies are enabled with certain certificate setups. Palo Alto patched it May 13, but active exploitation started days later and CISA had it on the must-patch-in-72-hours list by May 29.
Arctic Wolf Labs has since tracked Qilin affiliates using it as a reliable front door: get the VPN session, dump credentials and the Active Directory database, move laterally over admin shares, then drop ransomware — sometimes fast encryption-only jobs, sometimes the full double-extortion treatment, depending on which affiliate drew the short straw.
Ransomware-as-a-Service, Now With Franchise Variety
The inconsistency in post-exploitation tactics is the tell: this isn't one crew, it's a ransomware-as-a-service operation with multiple affiliates running the same entry technique but improvising everything after the door opens. Same key, different burglars.
The real headline isn't the exploit — it's the gap. A patch has existed for over two months and organizations are still getting hit, which says less about Palo Alto's fix and more about how many networks never got around to applying it.
If your GlobalProtect gateway hasn't been patched since May, congratulations, you're the reason this story keeps getting written.
Source: The Hacker News