Qilin ransomware is exploiting a critical PAN-OS GlobalProtect auth bypass to breach networks — confirmed by Arctic Wolf. Patch now if you run Palo Alto gear: enterprises directly, smaller shops via whoever manages your firewall. Edge VPNs remain the top ransomware entry point.Cyber Resilience desk
Sources (3)
- bleeping · bleeping
- cisa_advisories · cisa_advisories
- securityweek · securityweek
What this means for you — CISO:Arctic Wolf confirms Qilin is exploiting a critical PAN-OS GlobalProtect auth bypass for initial access. Patch GlobalProtect gateways now and check logs for the CVE's known exploitation indicators.
What this means for you — Lean IT orgs:If you use a Palo Alto firewall for remote access, get the GlobalProtect patch installed now — ransomware crews are actively using this bug to break in. If you don't run Palo Alto gear, this one doesn't apply to you.
What this means for you — MSP:Inventory every client running PAN-OS GlobalProtect and prioritize this patch above routine cycles — active ransomware exploitation means delay translates directly into breach risk across your book.
What this means for you — Researcher:Arctic Wolf ties Qilin activity to a critical GlobalProtect auth bypass; worth checking whether the exploitation pattern matches prior PAN-OS bugs used by other ransomware affiliates or represents new tradecraft.