BoletimSecJuly 22, 2026🇵🇹Translated from Portuguese

Qilin Ransomware Operators Exploit Palo Alto PAN-OS VPN Flaw CVE-2026-0257

Operators linked to the Qilin ransomware have exploited an authentication bypass flaw in Palo Alto Networks PAN-OS to breach corporate networks and encrypt systems. The attacks, first observed in June 2026, began through the GlobalProtect VPN service installed on Palo Alto firewalls.

Tracked as CVE-2026-0257, the vulnerability allows attackers to circumvent authentication and establish VPN sessions without valid credentials. Exploitation requires the use of crafted authentication-replacement cookies combined with specific certificate configurations.

After obtaining initial access, the intruders collected credentials from Windows and Active Directory, including data extracted from LSASS processes and NTDS databases. Compromised administrative accounts were then used to reach servers, workstations, and backup systems.

Lateral movement was conducted primarily via PsExec and administrative shares. Additional tools observed in some intrusions included AnyDesk, Ngrok, LogMeIn, NetExec, and various network scanners employed to expand and maintain access.

Prior to encryption, the operators disabled Microsoft Defender real-time protection and cleared event logs. The ransomware payload was stored as win.exe, typically inside the C:\PerfLogs\ directory. Some victims experienced only partial encryption of their systems.

The flaw impacts vulnerable versions of PAN-OS 10.2, 11.1, 11.2, and 12.1, as well as certain editions of Prisma Access. Panorama and Cloud NGFW are not affected. The vendor has confirmed limited exploitation attempts against unpatched devices.

Related articles

BoletimSecRansomware & Extortion

Ransomware Groups Disable EDR, Backups and Windows Telemetry Before Encryption

Ransomware operators are increasingly focusing on disabling endpoint detection and response tools, backup systems, and Windows telemetry mechanisms prior to launching encryption. An analysis of the ten ransomware families with the lowest prevention rates in 2026 found that Play achieved only 13 percent of attacks blocked. BlackByte followed with 25 percent blocked and LockBit with 30 percent blocked. BabLock leverages a legitimate uninstaller to remove endpoint protection and terminates processes belonging to antivirus, EDR, backup, and database applications. It then clears the Security and System event logs to hinder incident response. LockBit 5.0 instead interferes with Event Tracing for Windows to reduce visibility for monitoring solutions. Additional families employ process injection, in-memory execution, registry modifications, file masquerading, and living-off-the-land binaries to evade detection.

安全客Ransomware & Extortion

Chinese Courts Hand Down 16-Year and 32-Year Sentences to Ransomware Operators

Two individuals involved in ransomware operations have received lengthy prison terms in China, with one sentenced to 16 years and the other to 32 years. The cases underscore Beijing's increasing focus on prosecuting ransomware-related crimes. The longer sentence reflects the scale and impact of the criminal activity attributed to the second defendant. Chinese authorities have publicly highlighted these outcomes as part of broader efforts against cyber extortion. The rulings send a clear deterrent message to ransomware actors operating within or targeting Chinese infrastructure.

AntiMalwareRansomware & Extortion

Telegram Removed from App Store After Extortionist Plants AI-Modified CSAM in Archived Message

Pavel Durov stated that an extortionist edited an old public group message by inserting AI-altered child sexual abuse material, allowing the post to evade detection by active chat participants while enabling a direct report to Apple. The tactic triggered automatic removal of Telegram and experimental Telegram X from the App Store in multiple countries including Russia, Turkey, and the United States on August 4. Apple restored the applications after Telegram deleted the prohibited content and blocked the responsible account, with the entire outage lasting approximately ninety minutes. During the incident, push notifications failed for some iOS users, while macOS and Android versions remained unaffected. Durov criticized Apple for suspending the app without prior contact and warned that the same mechanism could be used against any user-generated content platform. Telegram urged Apple to apply equal scrutiny to all incoming reports rather than acting on isolated complaints that bypass normal moderation filters.

BoletimSecRansomware & Extortion

Cl0p Exploits Critical Windchill Vulnerability CVE-2026-12569 to Steal Industrial Designs

The Cl0p extortion group is actively targeting internet-exposed PTC Windchill and FlexPLM servers to exfiltrate engineering projects, technical specifications, and other sensitive data. The campaign focuses on organizations in the industrial, automotive, aerospace, defense, and retail sectors. Attackers leverage the critical remote code execution vulnerability CVE-2026-12569, which stems from unsafe deserialization and carries a CVSS score of 9.8, allowing unauthenticated exploitation over the network. The intrusion chain also combines a WSDL endpoint information disclosure in FlexPLM with a login mechanism weakness in Windchill to gain initial access and execute commands without valid credentials. After compromise, operators deploy JSP web shells to maintain persistence, explore files, and prepare data for exfiltration. Affected systems often contain unreleased product designs, engineering drawings, and strategic manufacturing documents. The activity began in early June 2026, with extortion emails sent to hundreds of employees starting July 20 to increase internal pressure ahead of potential data leaks.