<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Palo-Alto on CuraSec</title><link>https://curasec.metacog.co.kr/tags/palo-alto/</link><description>Recent content in Palo-Alto on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 21 Jul 2026 12:43:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/palo-alto/index.xml" rel="self" type="application/rss+xml"/><item><title>Qilin ransomware exploits critical PAN-OS GlobalProtect auth bypass</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A critical authentication bypass in PAN-OS GlobalProtect is being actively weaponized for ransomware intrusions — patch PAN-OS to the fixed version listed in Palo Alto&amp;rsquo;s advisory immediately, and audit VPN authentication logs for anomalous sessions preceding lateral movement.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Qilin&amp;rsquo;s use of a VPN auth bypass as initial access means compromise may precede any patch; if GlobalProtect is in your environment, run an assume-breach hunt now — look for anomalous GlobalProtect auth events, unusual post-VPN lateral movement, and Qilin-associated TTPs documented in Arctic Wolf&amp;rsquo;s reporting.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Active ransomware exploitation of a widely-deployed VPN product is a board-question-level event — confirm this week whether GlobalProtect is in your estate, verify emergency patching is underway, and prepare a short leadership brief in case an incident surfaces.&lt;/li>
&lt;/ul></description></item></channel></rss>